UPSTREAM FIX

magento2-38804: Update js.phtml DOM text reinterpreted as HTML

Community fix magento2-38804 merged into magento/magento2 on 2026-06-16, not in a release yet; applies cleanly to 34 releases from 2.4.6 to 2.4.9.

Pull request title
Update js.phtml DOM text reinterpreted as HTML
Pull request
magento/magento2#38804
Issues
#38821 pr-derived
Author
@Shivam7-1
Merged
2026-06-16
Fixed in
no release yet
Reported on
—
Categories
Admin
Components
magento/module-catalog

Labels

Area
Security
Component
Backend
Priority
P2
Severity
—
Reported on (labels)
2.4.x

Issue

Title and steps come from the upstream issue and pull request.

Description

By using innerText, it will avoid the risk of HTML injection, as these properties automatically escape any HTML special characters in the provided text. This helps prevent cross-site scripting (XSS) vulnerabilities by treating the input as plain text rather than interpreted HTML.

Taken from the upstream pull request.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 clean
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 92.3%. Probability it is security relevant: 97.2%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 89.4%, refactor 6.3%, dependency 1.3%, feature 1.2%, docs_only 1.0%, tests_only 0.9%76.3%
Areaadminadmin 44.0%, catalog 28.8%, frontend 19.8%21.9%
Reported versionunspecifiedunspecified 27.4%, 2.4.6 2.4%, 2.4.7 2.0%7.2%
Scope0.12 of 20 90.4%, 1 7.3%, 2 2.3%73.5%
Risk0.40 of 20 63.6%, 1 33.1%, 2 3.3%27.3%
Worth backporting1.57 of 22 65.9%, 1 25.4%, 0 8.7%26.0%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-38804/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-catalog
Bundle README (what the ZIP ships)
# magento2-38804

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/38804
Issue: https://github.com/magento/magento2/issues/38821
Author: @Shivam7-1
Source commit: 0335a3de1ca4a34a45096a53b862690b12a31d6e
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.