Why Nostr? What is Njump?
2024-01-19 13:47:53

bert hubert πŸ‡ΊπŸ‡¦πŸ‡ͺπŸ‡Ί on Nostr: And another unfortunate security thing I learned today is that .svg files can contain ...

And another unfortunate security thing I learned today is that .svg files can contain JavaScript, and that your browser will happily execute that if someone directly views your image (so not through <img>). This has consequences for anyone hosting user supplied images. Thank you Wander Nauta for pointing this out. The painful story is here: https://github.com/berthubert/trifecta/issues/38
Author Public Key
npub1k2njntmj75l277nyj39rkn7vrfwyu3rks54cq5fm7sz3s0zggxrsseu4xq