This article discusses some vulnerabilities with HTML and SVG on S3: https://env.fail/posts/aws-s3/ this can strip javascript from svg: https://github.com/svg/svgo