Skip to main content
← Back to Demos
Script Injection beginner · 15 min

SVG image with script payload in onload handler

A reported Bing Images issue shows how dangerous vector graphics can be: crafted SVG files were found able to execute commands as SYSTEM on Microsoft's servers. SVG is a text-based markup format, so it can carry JavaScript inside element handlers, and rendering an innocuous-looking image can silently run that script in the application's security context. Attackers weaponize this to drop payloads, steal cookies, or pivot within a session. In this demo a benign SVG runs only a harmless onload alert to illustrate the mechanism. Deep CDR parses and rebuilds the SVG, stripping script and ActiveX-style content while preserving the visual output. A sanitized image reaches the endpoint — no executable script ever runs.

Attack Technique

SVG embedded script

MITRE ATT&CK

T1059.007 ↗

Platforms

linuxwindows

File Types

.svg

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---