- From: Yehonatan Daniv via GitHub <noreply@w3.org>
- Date: Thu, 25 Jun 2026 08:32:09 +0000
- To: public-svg-issues@w3.org
I looked up security issues related to `requiredExtensions`, found a little about XSS/injection specific to HTML. Other than that, it's mostly using more obscure extensions for stuff like fingerprinting, SVG smuggling, evasion of static filters, phishing, and malicious redirection. So limiting to MathML and HTML seems to help avoid most cases. But maybe we need a security expert here to weigh in to consider HTML as well? -- GitHub Notification of comment by ydaniv Please view or discuss this issue at https://github.com/w3c/svgwg/issues/138#issuecomment-4797325181 using your GitHub account -- Sent via github-notify-ml as configured in https://github.com/w3c/github-notify-ml-config
Received on Thursday, 25 June 2026 08:32:10 UTC