4 ms·
I see a big security problem with SVG: browsers allow executing scripts in SVG files in site security context, so you have to check for a lot of script executio
by ingenter 11y ago
I see a big security problem with SVG: browsers allow executing scripts in SVG files in site security context, so you have to check for a lot of script execution vectors in SVG before you allow uploading user files.
https://github.com/wikimedia/mediawiki/blob/4aa9e1/includes/upload/UploadBase.php#L1128 https://github.com/wikimedia/mediawiki/blob/4aa9e1/includes/...
https://github.com/wikimedia/mediawiki/blob/4aa9e1/includes/upload/UploadBase.php#L1293 https://github.com/wikimedia/mediawiki/blob/4aa9e1/includes/...
- the8472 11y agomy understanding is that svg in <img> is safe but prevents script execution svg in iframe + srcdoc + sandbox gives you sortof-inline svg with separate security contexts. only plain inlined svg should be a security risk.
- ingenter 11y agoIf you host SVG file on the same domain as the main site, I can give a direct link to the SVG file and your browser will execute arbitrary JavaScript in that context.
- the8472 11y agoI think in that case setting the CSP sandbox header to "allow-scripts" would have the same effect as the iframe sandbox attribute and allow script execution in the SVG but prevent same-origin access and various other things.