[galaxy-dev] using svg foreignObject tags can circumvent html sanitization