Issue
After updating to Pega Infinity™ '25.1.1, outbound HTML correspondence emails that use <pega:include> tags within href attributes of button-style links stop functioning. Recipients receive emails with non-functional links. When the link URL is inspected, it contains Pega's render:/// scheme with the URL-encoded literal text of the include directive rather than the resolved external URL.
Symptoms and Impact
-
Button links in HTML email correspondence that composed their href values by referencing a Rule-HTML-Paragraph URL fragment via <pega:include> no longer resolve at send time.
-
Inspecting the raw email source reveals the unresolved render:/// URL containing the encoded <pega:include> directive text.
-
The issue appears after saving or checking in a Rule-HTML-Paragraph rule on Infinity '25.1.1, at which point the <pega:include> tag inside the href attribute is converted to its HTML-escaped form (<pega:include>), preventing Pega Platform™ from processing and expanding the directive at correspondence send time.
Steps to Reproduce
- On Pega Platform 25.1.1, open a Rule-HTML-Paragraph rule used in outbound correspondence that contains a button-style row where the href value is built using a <pega:include> reference to a URL-fragment paragraph.
- Save or check in the paragraph rule. The <pega:include> tag inside the href attribute is converted to its HTML-escaped form (<pega:include>).
- Trigger a correspondence Send for a case with valid primary page and resource settings.
-
Open the received email and copy the link from the button (or view the message source). Result: The link uses the render:/// URL scheme and contains the URL-encoded pega:include tag text instead of the expected resolved external URL.
Root Cause
This behavior is the result of RTE (Rich Text Editor) security hardening progressively introduced in Pega Platform. As documented in the Pega Platform security guidance for Rich Text Editor controls, Pega has been tightening RTE security controls to reduce the risk of HTML injection and cross-site scripting (XSS) vulnerabilities.
As part of these security controls, Pega reference tags — including <pega:include> — are no longer permitted by default within RTE-authored content in Pega Platform '25.1.1. When such tags are present inside HTML attributes (such as href) in a Rule-HTML-Paragraph, saving the rule causes the RTE to escape the tag to its HTML-encoded equivalent, rendering it inert at correspondence render time.
This is consistent with the broader RTE security hardening first introduced in the I23 Security Advisory (affecting releases from Pega Platform 8.3.6 and 8.8.3 onward) and carried forward into Pega Infinity '25 releases.
Solution
Enable the RTEAllowPegaReferenceTags Dynamic System Setting (DSS).
Enabling the RTEAllowPegaReferenceTags DSS restores the previous behavior, allowing <pega:include> tags to be preserved and processed correctly within RTE-authored content at correspondence send time.
DSS Configuration:
- Setting name: RTEAllowPegaReferenceTags
- Owning Ruleset: Pega-ProcessCommander
- Value: true
Steps to configure:
- Navigate to .
- Search for RTEAllowPegaReferenceTags.
- If the record does not exist, create a new DSS record:
- Owning Ruleset: Pega-ProcessCommander
- Setting Purpose: RTEAllowPegaReferenceTags
- Value: true
- Save the record. No system restart is required.
- Re-save the affected Rule-HTML-Paragraph rules to allow the platform to reprocess them with the updated setting.
- Trigger a test correspondence send and verify that button links resolve to the expected external URLs.
The long-term recommended approach is to refactor correspondence rules to avoid reliance on <pega:include> tags within HTML attributes, using supported correspondence fragment patterns instead.