diff --git a/packages/scratch-svg-renderer/src/sanitize-svg.js b/packages/scratch-svg-renderer/src/sanitize-svg.js index e12886bdfe..c61f0f7e5d 100644 --- a/packages/scratch-svg-renderer/src/sanitize-svg.js +++ b/packages/scratch-svg-renderer/src/sanitize-svg.js @@ -128,7 +128,7 @@ sanitizeSvg.sanitizeByteStream = function (rawData) { */ sanitizeSvg.sanitizeSvgText = function (rawSvgText) { let sanitizedText = DOMPurify.sanitize(rawSvgText, { - USE_PROFILES: {svg: true}, + USE_PROFILES: {svg: true, svgFilters: true}, FORBID_TAGS: ['a', 'audio', 'canvas', 'video'], // Allow data URI in image tags (e.g. SVGs converted from bitmap) ADD_DATA_URI_TAGS: ['image']