magento2-40201: Escaper checking preg_replace results for false instead of null
Community fix magento2-40201 merged into magento/magento2 on 2025-11-19, released in 2.4.9; applies cleanly to 33 releases from 2.4.6 to 2.4.8-p5.
Fixes Escaper checking preg_replace results for false instead of null edited
- Pull request title
- Condition is never met in `\Magento\Framework\Escaper::escapeScriptIdentifiers`
- Pull request
- magento/magento2#40201
- Issues
- #40195 human
- Author
- @wubinworks
- Merged
- 2025-11-19
- Fixed in
- 2.4.9
- Reported on
- —
- Categories
- —
- Components
- magento/framework
Labels
- Area
- Framework
- Component
- Framework/Escaper
- Priority
- P2
- Severity
- —
- Reported on (labels)
- 2.4.x
Issue
Title and steps come from the upstream issue and pull request.
Description
$filteredData is false.Steps to reproduce
\Magento\Framework\Escaper::escapeScriptIdentifiers](https://github.com/magento/magento2/blob/4baea6d63e6cc645e7417998e930117d590c88a2/lib/internal/Magento/Framework/Escaper.php#L407):[Here](https://github.com/magento/magento2/blob/4baea6d63e6cc645e7417998e930117d590c88a2/lib/internal/Magento/Framework/Escaper.php#L410) and [here](https://github.com/magento/magento2/blob/4baea6d63e6cc645e7417998e930117d590c88a2/lib/internal/Magento/Framework/Escaper.php#L415),
$filteredData === false will never be met since preg_replace only returns string|array|null.See
preg_replace [documentation](https://www.php.net/manual/en/function.preg-replace.php#refsect1-function.preg-replace-returnvalues).Expected result
$filteredData is NULL.Actual result
$filteredData is false.Taken from the upstream issue.
Code match per tag
Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.
| Line | Code match per tag | Tests |
|---|---|---|
| 2.4.6 | 2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean | 2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data |
| 2.4.7 | 2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean | 2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data |
| 2.4.8 | 2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean | 2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data |
| 2.4.9 | 2.4.9 conflictcontains the fix | 2.4.9: no test data |
Triage
Model @cf/cloudflare/clef. Probability this is a bug fix: 92.1%. Probability it is security relevant: 93.7%.
Show the model's answers and probabilities
| Question | Answer | Probabilities | Confidence |
|---|---|---|---|
| Change kind | bugfix | bugfix 91.3%, refactor 6.4%, docs_only 0.6%, tests_only 0.6%, feature 0.5%, dependency 0.5% | 80.6% |
| Area | framework | framework 93.7%, frontend 2.4%, admin 0.9% | 86.2% |
| Reported version | unspecified | unspecified 39.4%, 2.4.6 1.8%, 2.4.3 1.4% | 15.0% |
| Scope | 1.01 of 2 | 1 85.3%, 2 8.0%, 0 6.7% | 60.9% |
| Risk | 0.31 of 2 | 0 72.4%, 1 24.2%, 2 3.4% | 37.7% |
| Worth backporting | 0.69 of 2 | 0 51.9%, 1 27.2%, 2 20.8% | 8.1% |
Download
For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40201/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.
Bundle README (what the ZIP ships)
# magento2-40201 Community fix merged upstream into magento/magento2, adapted by magento.watch. This is not a patch published by Adobe. Pull request: https://github.com/magento/magento2/pull/40201 Issue: https://github.com/magento/magento2/issues/40195 Author: @wubinworks Source commit: fea5af033bd77a27b4d1e2990c04d8f1c77db4f1 Modifications: test files and documentation removed, paths rewritten relative to each Composer package. Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code. Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)
Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.
