Avoid Flask markup helpers fed by request data
Flask responses should not bypass escaping when interpolating `request` input into HTML helpers or template strings.
#Metadata
#Why it matters
Markup helpers, render_template_string, and Jinja safe filters bypass escaping and commonly become XSS sinks.
#Remediation
Use automatic escaping, `render_template` with trusted contexts, or a vetted sanitizer instead of raw markup shortcuts.
#Repository path
The generated metadata points to critiq-rules/libs/rules/catalog/rules/python/py.security.flask-unsafe-html-output.rule.yaml.