Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> if not validated

I thought script tags were an official part of SVG? Meaning that a valid SVG can contain embedded JS.



he must have meant to 'sanitize' or 'filter'




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: