Skip to content

Commit b7818c9

Browse files
committed
Clarify unsafe option scope without removing security warning
1 parent 9e8c6ed commit b7818c9

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

cairosvg/surface.py

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -116,6 +116,10 @@ def convert(cls, bytestring=None, *, file_obj=None, url=None, dpi=96,
116116
:param unsafe: A boolean allowing external file access, XML entities
117117
and very large files
118118
(WARNING: vulnerable to XXE attacks and various DoS).
119+
This does NOT restrict fetching of the main SVG input specified via
120+
the ``url`` parameter.
121+
Applications should validate input URLs to prevent SSRF.
122+
119123
120124
Specifiy the output with:
121125

0 commit comments

Comments
 (0)