You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Will look into it, but I left it image/svg assuming there are more similar dangerous subtypes of SVG. If you can confirm image/svg+xml is the only exploitable type and some browsers won't execute JS in other subtypes, we can change it to image/svg+xml. There is not much information or general consensus between browsers on this yet.
It seem like the 0e456c2 commit used 'image/svg' instead of 'image/svg+xml'. I wasn't able to comment on that commit by the way.
The text was updated successfully, but these errors were encountered: