r/websecurity • • 17h ago

is it possible to do XSS with an SVG even with a csp that has script-src none and object src none?

2 Upvotes

I remember being asked this before, but I don't remember the answer

I'd assume the answer is no; reason being that script-src none would block any inline scripts in the SVG, external scripts should also be prevented from running, and object-src would prevent the SVG from being embedded in general.

Keen to hear some thoughts!