4 ms·
One case where you probably can't is for image uploads. You might think it would be nice to allow a user to upload a svg for their avatar or something. But SVG
by throwaway_bad 7y ago
One case where you probably can't is for image uploads. You might think it would be nice to allow a user to upload a svg for their avatar or something.
But SVG can embed javascript which can lead to XSS: https://hackerone.com/reports/148853 https://hackerone.com/reports/148853
- pekim 7y agoThat's certainly something to be considered with user uploaded svg images. However it's reasonably straightforward to parse an svg and remove any script elements.
- microcolonel 7y agoYou can safely use XSLT to subset SVG, and (for example) limit complexity. Scripts in SVGs do not load in img tags either.