UPSTREAM FIX

magento2-40870: Broken admin product gallery when an image attribute label has a quote

Community fix magento2-40870 merged into magento/magento2 on 2026-07-28, not in a release yet; applies cleanly to 2.4.9.

Fixes broken admin product gallery when an image attribute label has a quote edited

Pull request title
Fixed: image attribute contains single quote
Pull request
magento/magento2#40870
Issues
#40519 pr-derived
Author
@aasim110
Merged
2026-07-28
Fixed in
no release yet
Reported on
—
Categories
—
Components
magento/module-product-video

Labels

Area
Content / CMS
Component
MediaGallery
Priority
P2
Severity
—
Reported on (labels)
2.4.x

Issue

Title and steps come from the upstream issue and pull request.

Steps to reproduce

1. Create an image attribute with a label containing a single quote (e.g. Image d'exemple)
2. Assign it to some attribute set
3. Edit any corresponding product in the admin and open the gallery tab: the gallery is broken

Taken from the upstream pull request.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 conflict 2.4.6-p1 conflict 2.4.6-p2 conflict 2.4.6-p3 conflict 2.4.6-p4 conflict 2.4.6-p5 conflict 2.4.6-p6 conflict 2.4.6-p7 conflict 2.4.6-p8 conflict 2.4.6-p9 conflict 2.4.6-p10 conflict 2.4.6-p11 conflict 2.4.6-p12 conflict 2.4.6-p13 conflict 2.4.6-p14 conflict 2.4.6-p15 conflict
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 conflict 2.4.7-p1 conflict 2.4.7-p2 conflict 2.4.7-p3 conflict 2.4.7-p4 conflict 2.4.7-p5 conflict 2.4.7-p6 conflict 2.4.7-p7 conflict 2.4.7-p8 conflict 2.4.7-p9 conflict 2.4.7-p10 conflict
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data
2.4.8
2.4.8 conflict 2.4.8-p1 conflict 2.4.8-p2 conflict 2.4.8-p3 conflict 2.4.8-p4 conflict 2.4.8-p5 conflict
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data
2.4.9
2.4.9 clean
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 98.0%. Probability it is security relevant: 83.5%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 97.6%, refactor 0.9%, feature 0.4%, dependency 0.4%, tests_only 0.4%, docs_only 0.3%94.3%
Areaadminadmin 66.3%, catalog 24.2%, frontend 6.0%43.1%
Reported versionunspecifiedunspecified 24.3%, 2.4.6 3.3%, 2.4.8 2.5%5.7%
Scope0.17 of 20 86.0%, 1 11.3%, 2 2.7%62.9%
Risk0.27 of 20 75.3%, 1 22.8%, 2 1.8%43.0%
Worth backporting1.67 of 22 73.7%, 1 19.6%, 0 6.8%37.8%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40870/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-product-video
Bundle README (what the ZIP ships)
# magento2-40870

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/40870
Issue: https://github.com/magento/magento2/issues/40519
Author: @aasim110
Source commit: ce4e0be9fc82d467b20661e9b65a5cff9fe2d51f
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.