lib/omniauth/failureendpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the messagekey value.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "1.9.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.0.0-pre\\.rc1"
}
]
}