←back to thread

An SVG is all you need

(jon.recoil.org)
281 points sadiq | 3 comments | | HN request time: 0.789s | source
1. felineflock ◴[] No.46240040[source]
"SVG Considered Harmful"

https://www.cloudflare.com/cloudforce-one/research/svgs-the-...

replies(2): >>46240219 #>>46242207 #
2. perilunar ◴[] No.46240219[source]
"Since SVGs are essentially code, they can embed JavaScript"

Odd thing to say. Everything on a computer is "essentially code", executable or not.

3. tomalbrc ◴[] No.46242207[source]
First off, what kind of SVG reader does cloudflare assume to just open SVGs and Willy nilly run contained js? Is that a windows os feature? Second, do they not know about Content Security Policies?

And as a side note: Cloudflare itself is considered harmful