UPSTREAM FIX

magento2-40423: GraphQL escaping special characters in the product name field

Community fix magento2-40423 merged into magento/magento2 on 2026-02-10, released in 2.4.9; applies cleanly to 6 releases from 2.4.8 to 2.4.8-p5.

Fixes GraphQL escaping special characters in the product name field edited

Pull request title
Unnecessarly escaped characters in ProductInterface
Pull request
magento/magento2#40423
Issues
#40178 human
Author
@yaroslav-kozar
Merged
2026-02-10
Fixed in
2.4.9
Reported on
2.4.8-p1
Categories
Catalog/Product, GraphQL
Components
magento/module-catalog-graph-ql

Labels

Area
Product
Component
GraphQL
Priority
P3
Severity
—
Reported on (labels)
2.4.8-p1

Issue

Title and steps come from the upstream issue and pull request.

Description

The GraphQL API returns the escaped greater than sign >

Steps to reproduce

1. In Magento admin, create a product with a special character in the name. For example >.
2. Query the name from that product using GraphQL.

Expected result

It should return unescaped > in the name.

Actual result

The GraphQL API returns the escaped greater than sign >

Taken from the upstream issue.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 file-missing 2.4.6-p1 file-missing 2.4.6-p2 file-missing 2.4.6-p3 file-missing 2.4.6-p4 file-missing 2.4.6-p5 file-missing 2.4.6-p6 file-missing 2.4.6-p7 file-missing 2.4.6-p8 file-missing 2.4.6-p9 file-missing 2.4.6-p10 file-missing 2.4.6-p11 file-missing 2.4.6-p12 file-missing 2.4.6-p13 file-missing 2.4.6-p14 file-missing 2.4.6-p15 file-missing
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 file-missing 2.4.7-p1 file-missing 2.4.7-p2 file-missing 2.4.7-p3 file-missing 2.4.7-p4 file-missing 2.4.7-p5 file-missing 2.4.7-p6 file-missing 2.4.7-p7 file-missing 2.4.7-p8 file-missing 2.4.7-p9 file-missing 2.4.7-p10 file-missing
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: test files do not apply to this releaseapi-functional: could not run before, could not run after
2.4.9
2.4.9 file-missingcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 98.1%. Probability it is security relevant: 84.2%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 94.3%, refactor 2.7%, tests_only 1.3%, feature 0.6%, dependency 0.6%, docs_only 0.5%86.9%
Areagraphql_apigraphql_api 87.8%, catalog 9.5%, framework 0.6%74.8%
Reported version2.4.8-p12.4.8-p1 62.1%, 2.4.8-p2 3.6%, 2.4.8 2.1%38.2%
Scope0.74 of 21 52.4%, 0 36.9%, 2 10.7%13.3%
Risk0.58 of 20 51.6%, 1 38.3%, 2 10.1%13.5%
Worth backporting1.58 of 22 66.4%, 1 24.9%, 0 8.7%26.6%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40423/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-catalog-graph-ql
Bundle README (what the ZIP ships)
# magento2-40423

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/40423
Issue: https://github.com/magento/magento2/issues/40178
Author: @yaroslav-kozar
Source commit: 3069256c2869c363ab0686de5ff4fa16085f7671
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.