View all

comments

Highlighted comment

you can upload svg avatars, they just get converted to png because xss

so technically every account (except ones with default pfps) is png

i’m pretty sure svgs in <img> tags cannot run scripts and stuff