7 ms·
The fact that SVG files can contain scripts was a bit of a mistake. On one hand, the animations and entire interactive demos and even games in a single SVG are
by dllu 10mo ago
The fact that SVG files can contain scripts was a bit of a mistake. On one hand, the animations and entire interactive demos and even games in a single SVG are cool. But on the other hand, it opens up a serious can of worms of security vulnerabilities. As a result, SVG files are often banned from various image upload tools, they do not unfurl previews, and so on. If you upload an SVG to discord, it just shows the raw code; and don't even think about sharing an SVG image via Facebook Messenger, Wechat, Google Hangouts, or whatever. In 2025, raster formats remain way more accessible and easily shared than SVGs.
This is very sad because SVGs often have way smaller file size, and obviously look much better at various scales. If only there was a widely used vector format that does not have any script support and can be easily shared.
- nightski 10mo agoDoes it need to be as complicated as a new format? Or would it be enough to not allow any scripting in the provided SVGs (or stripping it out). I can't imagine there are that many SVGs out there which take advantage of the feature.
- culi 10mo agoDo other vector formats have the same vulnerabilities?
- bobbylarrybobby 10mo agoWould it be possible for messenger apps to simply ignore <script> tags (and accept that this will break a small fraction of SVGs)? Or is that not a sufficient defense?
- demurgos 10mo agoI looked into it for work at some point as we wanted to support SVG uploads. Stripping <script> is not enough to have an inert file. Scripts can also be attached as attributes. If you want to prevent external resources it gets more complex. The only reliable solution would be an allowlist of safe elements and attributes, but it would quickly cause compat issues unless you spend time curating the rules. I did not find an existing lib doing it at the time, and it was too much effort to maintain it ourselves. The solution I ended up implementing was having a sandboxed Chromium instance and communicating with it through the dev tools to load the SVG and rasterize it. This allowed uploading SVG files, but it was then served as rasterized PNGs to other users.
- MarsIronPI 10mo agoShouldn't the ignoring of scripting be done at the user agent level? Maybe some kind of HTTP header to allow sites to disable scripts in SVG ala CORS?
- staticassertion 10mo agoNo, svgs can do `onload` and `onerror` and also reference other svgs that can themselves contain those things (base64'd or behind a URI). But you can use an `img` tag (`<img src="evil.svg">`) and that'll basically Just Work, or use a CSP. I wouldn't rely on sanitizing, but I'd still sanitize.
- collinmanderson 10mo ago> But you can use an `img` tag (`<img src="evil.svg">`) and that'll basically Just Work That doesn't help too much if evil.svg is hosted on the same domain (with default "Content-Type: image/svg+xml" header), because attacker can send a direct link to the file.
- GoblinSlayer 10mo agoReddit horribly breaks direct links to images and serves html instead.
- FeepingCreature 10mo agoIf only there was a widely used vector format that had script support and also decades of work on maintaining a battle-tested security layer around it with regular updates on a faster release cycle than your browser. That'd be crazy. Sure would suck if we killed it because we didn't want to bother maintaining it anymore. (Yes I'm still salty about Flash.)
- lambdaone 10mo agoSVG without <script> would do just fine.
- naasking 10mo agoSVG also supports event attributes, so you should probably strip those too.
- JoshTriplett 10mo ago> because we didn't want to bother maintaining it anymore That wasn't the only reason. Flash was also proprietary, and opaque, and single-vendor, among many other problems with it.
- ajross 10mo agoUh... Flash was a genuine firehose of security flaws. I mean, yeah, they patched them. So "battle tested security layer" isn't wrong in a technical sense. But, yikes, no.
- acheron 10mo agoThe Flash revisionism I see around here occasionally is bizarre. No, Flash was terrible and killing it was good.
- FeepingCreature 10mo agoI think it depends on whether you see Flash as competing with webvideo or with downloadable executables.
- poorman 10mo agoAll SVGs should be properly sanitized going into a backend and out of it and when rendered on a page. Do you allow SVGs to be uploaded anywhere on your site? This is a PSA that you're probably at risk unless you can find the few hundred lines of code doing the sanitization. Note to Ruby on Rails developers, your active storage uploaded SVGs are not sanitized by default.
- ivw 10mo agojust run them through `svgo` and get the benefits of smaller filesizes as well
- silverwind 10mo agosvgo is a minifier, not a sanitizer.
- ivw 10mo agoI should have clarified `svgo + removeScripts` https://svgo.dev/docs/plugins/removeScripts/ https://svgo.dev/docs/plugins/removeScripts/
- poorman 10mo agoGitLab has some code in their repo if you want to see how to do it.
- jdironman 10mo agoThis is what they actually use: https://github.com/flavorjones/loofah https://github.com/flavorjones/loofah
- nradov 10mo agoIs there SVG sanitization code which has been formally proven correct and itself free of security vulnerabilities?
- rcxdude 10mo ago
- SV_BubbleTime 10mo ago> On one hand, the animations and entire interactive demos and even games in a single SVG are cool. But on the other hand Didn’t we do this already with Flash? Why would this lesson not have stuck?
- fainpul 10mo ago"The script doesn't run unless the file is directly opened (you can't run scripts from (<img src="/image.svg">)."
- kevin_thibedeau 10mo agoIt will run if its in an <object> tag.
- amonith 10mo agoSo if you're directly embedding the thing. This is a somewhat rare use case, should not be banned almost anywhere...
- username223 10mo agoIt's wild how often we rediscover that executing untrusted code leads to decades of whack-a-mole security. Excel/Word plus macros, HTML plus JavaScript, SVG plus JavaScript, ...
- eastbound 10mo agoIt’s wild how often specs are ok for 9 versions, and then at version 10, standard bodies decide to transform them into a trojan firehose. It’s so regular like clockwork that it has to be a nation state doing this to us.
- moss_dog 10mo agoAny notable examples you can share?
- kevin_thibedeau 10mo agoPDF was purposely a non-Turing adaptation of PostScript. Then they added JavaScript support.
- aidenn0 10mo agoExternal entities in XML[1] were a similar issue back when everyone was using XML for everything, and parsers processed external-entities by default. 1: https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing https://owasp.org/www-community/vulnerabilities/XML_External...
- hinkley 10mo agoAt least with external entities you could deny the parser an internet connection and force it to only load external documents from a cache you prepopulated and vetted. Turing completeness is a bullshit idea in document formats.
- aidenn0 10mo agoWith SVGs you can serve them from a different domain. IIUC the issue from TFA was that the SVGs were served from the primary domain; had they been on a different domain, they would have not been allowed to do as much.
- actionfromafar 10mo agoPostscript is pretty neat IMHO and it’s Turing complete. I really appreciated my raytraced page finally coming out of that poor HP laser after an hour or so.
- aidenn0 10mo agoI once sent a Sierpinski's Triangle postscript program to a shared printer. It took 90 minutes, and pissed off everybody else trying to print.
- hinkley 10mo agoOne of the very first SVG documents I encountered was a port of the PS Tiger to SVG. It loaded a lot faster than the PostScript Tiger.
- bigfatkitten 10mo agoSounds almost like a fun crypto mining opportunity.
- aydyn 10mo agoThere is: PDF. You may not like it or adobe, but its there and widely supported.
- anthk 10mo agoBetter a DJVU file generated at a high DPI.
- Shared404 10mo agoPDF also has script support unfortunately.
- mikkupikku 10mo agoThat's apparently how 4chan got hacked a while back. They were letting users upload PDFs and were using ghostscript to generate thumbnails. From what I understand, the hackers uploaded a PDF which contained PostScript which exploited a ghostscript bug.
- diath 10mo agoYes but the primary issue was that 4chan was using over a decade old version of the library that contained a vulnerability first disclosed in 2012: https://nvd.nist.gov/vuln/detail/CVE-2012-4405 https://nvd.nist.gov/vuln/detail/CVE-2012-4405
- jonahx 10mo agoDoes that mean that opening arbitrary pdfs on your laptop is unsafe?
- bmacho 10mo agoYes, opening random pdfs especially in random and old pdf viewers is not a good idea. If you must open a possibly infected pdf, then do it in browser, pdf.js is considered mostly safe, and updated.
- msie 10mo agoWow, I learned one thing today!
- HPsquared 10mo agoCould there be a limited format that disables scripting? Like in Excel: xlsx files have no macros, but xlsm (and the old xls) can contain macros.
- Wowfunhappy 10mo agoIMO, the bigger problem with SVGs as an image format is that different software often renders them (very) differently! It's a class of problem that raster image formats basically don't have.
- zffr 10mo agoI would have expected SVGs to be like PDFs and render the same across devices. Is the issue that some renderers don’t implement the full spec, or that some implement parts incorrectly?
- lenzm 10mo agoThey are like PDFs in that they do not render the same with different software or on different devices.
- 0x1ch 10mo agoWe live in a world where Adobe set the standard, and anything that didn't render like Adobe was considered "incorrect".
- Wowfunhappy 10mo agoI would say PDFs are actually reasonably consistent though. Weird things happen on occasion, but I've certainly had more success than with SVGs.
- auxiliarymoose 10mo agoThey are reasonably consistent because there is a de-facto reference implementation (Adobe Acrobat) which, if your implementation does not match exactly, users will think your implementation is broken. There isn't such an implementation for SVG.
- eek2121 10mo agoYou definitely don't understand PDFs, let alone SVGs. PDFs can also contain scripts. Many applications have had issues rendering PDFs. Don't get me wrong, the folks creating the SVG standard should've used their heads. This is like the 5th time (that I am aware of) this type of issue has happened, (and at least 3 of them were Adobe). Allowing executable code in an image/page format shouldn't be a thing.
- css_apologist 10mo agois santizing SVGs hard, or just everyone forgets they can contain js?
- AmbroseBierce 10mo agoUser name checks out.
- coolcoder613 10mo agoI believe the username is from the AI simulation of HN in 10 years.
- rslashuser 10mo agoI gather from the HN discussion that it's not simple to disable scripting in an SVG, in retrospect a tragically missing feature. I guess the next step is to propose a simple "noscripting" attribute, which if present in the root of the SVG doc inhibits all scripting by conforming renderers. Then the renderer layer at runtime could also take a noscripting option, so the rendering context could force it if appropriate. Surely someone at HN is on this committee, so see what you can do! Edit: thinking about it a little more - maybe it's best to just require noscripting as a parameter to the rendering function. Then the browsers can have a corresponding checkbox to control SVG scripting and that's it.
- css_apologist 10mo agoits common to santize html string to parse it and remove/error on script tags (and other possible vulnerabilities) i wonder do people not do this with svgs?
- deleted 10mo ago[deleted]
- staticassertion 10mo agoDisabling script execution in svgs is very easy, it's just also easy to not realize you're about to embed an svg. `<img src="evil.svg">` will not execute scripts, a bit like your "noscripting" attribute except it's already around and works. Content Security Policy will prevent execution as well, you should be setting one for image endpoints that blocks scripts. Sanitizing is hard to get right by comparison (svgs can reference other svgs) but it's still a good idea.
- hoppp 10mo agoI agree, when animating SVGs I never put the js inside them so having the ability embed it is just dangerious I think
- Gander5739 10mo agoWikipedia, which allows uploading media, deals with this by rendering svgs on the server side.
- IgorPartola 10mo agoBut how else would we revisit all the security bugs of Flash/Macromedia?
- socalgal2 10mo agoIIUC, an untrusted inline SVG is bad. An image tag pointing to an SVG is not. <img src="untrusted.svg"> <!-- this is ok --> <svg from untrusted src> <!-- this is not ok --> I feel like this is common knowledge. Just like you don't inject untrusted HTML into your page. Untrusted HTML also has scripts. You either sanitize it. OR you just don't allow it in the first place. SVG is, at this point, effectively more HTML tags.
- auxiliarymoose 10mo agoAlso remember that if the untrusted SVG file is served from the same origin and is missing a `Content-Disposition: attachment` header (or a CSP that disables scripts), an attacker could upload a malicious SVG and send the SVG URL to an unsuspecting user with pretty bad consequences. That SVG can then do things like history.replaceState() and include <foreignObject> with HTML to change the URL shown to the user away from the SVG source and show any web UI it would like.
- socalgal2 10mo agohow is that special/different from an HTML URL?
- auxiliarymoose 10mo agoBecause displaying user-submitted images is pretty common and doesn't feel like a security footgun, but displaying user-submitted HTML is less common (and will raise more careful security scrutiny).
- deleted 10mo ago[deleted]
- Pxtl 10mo agoWhat we got was html for vector graphics and what we wanted was jpeg for vector graphics.
- zahlman 10mo agoYeah, it's still insane to me that the SVG can contain scripts. Wholly unnecessary; the DOM subtree it defines could be manipulated by external scripts just fine. Anyway, I just set `svg.disabled` in Firefox. Scary world out there.
- zahlman 10mo agoUpdate: this breaks quite a few things. It seems legitimate SVGs are used more often for UI icons than random diagrams and such. I suppose I shouldn't be surprised. I'll have to rethink this.