🚨 Improving SVG Handling: Security & Safety Enhancements #8
mayank1513
announced in
Announcements
Replies: 1 comment
-
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
We’ve recently improved how
@m2d/imagehandles SVG parsing.Previously, raw SVG strings were directly attached to the DOM for cropping away extra spaces. While usage was limited, this introduced a theoretical XSS / DOM injection risk if SVG input came from an untrusted @source.
✅ Fix included in latest release:
@svg-fns/iobefore attaching to the DOM.💡 Why this matters:
📌 What you should do:
🙏 Thanks to the community members who raise thoughtful issues and contribute fixes. This project stays strong because of your support.
Beta Was this translation helpful? Give feedback.
All reactions