5 ms·
And what about SVG's with JavaScript? I once saw a security company reporting to disable user uploaded SVG's.
by edwinjm 2y ago
And what about SVG's with JavaScript? I once saw a security company reporting to disable user uploaded SVG's.
- tracker1 2y agoFortunately svg and (x)HTML aren't too horrible in being able to sanitize scripts or if. The use of CSS's access notwithstanding.
- thomas34298 2y agoJS in SVGs can be dangerous, but you can mitigate it using a CSP or by sending "Content-Disposition: attachment" so the file will be downloaded instead of being executed in your current browser context.
- deleted 2y ago[deleted]