https://rt.cpan.org/Ticket/Display.html?id=62095
...
<div id="content">
[%# Status and error messages %]
- <span class="message">[% status_msg || c.request.params.status_msg %]</span>
+ <span class="message">[% status_msg || c.request.params.status_msg | html %]</span>
<span class="error">[% error_msg %]</span>
[%# This is where TT will stick all of your template's contents. -%]
[% content %]