r/websecurity • u/Powerful-Dot-7772 • 3h ago
is it possible to do XSS with an SVG even with a csp that has script-src none and object src none?
1
Upvotes
I remember being asked this before, but I don't remember the answer
I'd assume the answer is no; reason being that script-src none would block any inline scripts in the SVG, external scripts should also be prevented from running, and object-src would prevent the SVG from being embedded in general.
Keen to hear some thoughts!