bert_hubert,
@bert_hubert@fosstodon.org avatar

And another unfortunate security thing I learned today is that .svg files can contain JavaScript, and that your browser will happily execute that if someone directly views your image (so not through <img>). This has consequences for anyone hosting user supplied images. Thank you Wander Nauta for pointing this out. The painful story is here: https://github.com/berthubert/trifecta/issues/38

brainsmoke,
@brainsmoke@mastodon.social avatar

@bert_hubert Reminds me of my oldest open bug report https://bugzilla.mozilla.org/show_bug.cgi?id=455100 ( https://pizzadoos.com slash death.svg )

rysiek,
@rysiek@mstdn.social avatar

@bert_hubert oh man I am having flashbacks to a particularly bad week several years ago when I had discovered same. :blobcateyes:

bert_hubert,
@bert_hubert@fosstodon.org avatar

@rysiek just found out they also support iframes...

rysiek,
@rysiek@mstdn.social avatar

@bert_hubert yup…

wtfpdf,
@wtfpdf@mastodon.social avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • tacticalgear
  • DreamBathrooms
  • khanakhh
  • mdbf
  • InstantRegret
  • magazineikmin
  • everett
  • cubers
  • rosin
  • Youngstown
  • slotface
  • ngwrru68w68
  • kavyap
  • thenastyranch
  • JUstTest
  • modclub
  • Durango
  • GTA5RPClips
  • cisconetworking
  • osvaldo12
  • ethstaker
  • Leos
  • tester
  • anitta
  • normalnudes
  • provamag3
  • megavids
  • lostlight
  • All magazines