diff --git a/modules/@angular/platform-browser/src/security/html_sanitizer.ts b/modules/@angular/platform-browser/src/security/html_sanitizer.ts index 4059c9f0b2..74a8779739 100644 --- a/modules/@angular/platform-browser/src/security/html_sanitizer.ts +++ b/modules/@angular/platform-browser/src/security/html_sanitizer.ts @@ -89,6 +89,14 @@ const HTML_ATTRS = 'scope,scrolling,shape,size,span,start,summary,tabindex,target,title,type,' + 'valign,value,vspace,width'); +// NB: This currently conciously doesn't support SVG. SVG sanitization has had several security +// issues in the past, so it seems safer to leave it out if possible. If support for binding SVG via +// innerHTML is required, SVG attributes should be added here. + +// NB: Sanitization does not allow
elements or other active elements (