lib/omniauth/failureendpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the messagekey value.
{
"nvd_published_at": "2022-08-18T23:15:00Z",
"cwe_ids": [
"CWE-116"
],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2022-08-31T18:47:40Z"
}