a441b5b8fe
After security review, it turns out we were too paranoid about <track src>. Its content is not actually active or dangerous. Fixes #10089.