SVG Security Risks - not just a scalable graphic::Embedding Scalable Vector Graphics (SVG) can expose websites to code injection. This article explores how SVGs work, the risks they pose, and how to mitigate them.

  • mo_ztt ✅
    link
    42 years ago

    So I’m not trying to be critical of educational content… but what this article is actually saying, surely isn’t earthshattering news. Basically what it boils down to is that embedding SVGs with an img tag is probably safe, but expanding a user-provided SVG into your web site’s code is definitely not safe.

    Like I say it’s fine to make an article for people who didn’t know that, but framing that as an SVG problem (instead of an expanding-user-provided-HTML-onto-your-website problem) and building fear-mongering around touching SVG files as a result doesn’t seem right to me.