The provided vulnerability information indicates a stored XSS in the inventory source 'code' field, but no specific functions are mentioned in any of the sources. While the vulnerability clearly exists in input handling/output rendering for the inventory source code field, the advisory materials (CVE, GHSA, FriendsOfPHP YAML) don't disclose concrete function names or file paths. Magento's patch notes and commit diffs are not available in the provided context, making it impossible to identify specific vulnerable functions with high confidence. The XSS likely occurs in template rendering or form handling code related to inventory source management, but insufficient technical details prevent precise function identification.