Developer Toolbox

image/svg+xml

image/svg+xml is the type for SVG images. Unlike other image types, SVG is an XML document that can carry scripts and links, so how you serve it matters as much as the type itself.

Open in cURL Builder A request with this type is filled in.

Header

Content-Type: image/svg+xml

At a glance

Extensions
.svg
Kind
Text
Parameters
None
In a browser
Renders the image. Opened directly rather than through <img>, it is a document whose scripts run.

With curl

curl -o logo.svg -H 'Accept: image/svg+xml' https://example.com/logo.svg

With fetch

const res = await fetch('https://example.com/logo.svg');
const svg = await res.text(); // text, not a blob: SVG is XML

Common mistakes

  • Uploaded SVG can run scripts

    An SVG with <script> or an onload attribute, opened from your domain, runs with your cookies. Sanitize uploaded SVG, serve it with Content-Security-Policy: script-src 'none' or as an attachment, or convert it to PNG.

  • The wrong type breaks <img>

    Served as text/xml or text/plain, an SVG does not show in an <img> tag, which requires image/svg+xml.

  • Compress it

    SVG is text, so gzip or Brotli shrink it a lot. Check that your server compresses image/svg+xml: nginx, for one, compresses only text/html until you list more types in gzip_types.