But the XSS issues have nothing to do with the language choice. Python, ruby and any other langauge do nothing by default to protect you against such things either.
I agree this is a poor choice of code, and an attack vector, but the language used here is not to blame.