SECURITY: Ensure Message::rawParams can't lead to XSS