In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).
"https://github.com/pypa/advisory-database/blob/main/vulns/roundup/PYSEC-2025-69.yaml"