gi-docgen does not encode search terms before inserting them into HTML, allowing XSS via a crafted URL. The severity of this issue depends on what else is hosted on the same domain as the docs. XSS on a website that hosts only gi-docgen docs and nothing else is likely harmless.