{"success":true,"data":{"id":"svg-foreign-object-in-body","label":"SVG <foreignObject> embedded HTML (sandbox bypass)","description":"Email HTML body contains an SVG `<foreignObject>` element. `<foreignObject>` lets an SVG embed a whole XHTML payload (iframes, forms, password inputs, scripts) inside a namespace that mail-client sanitizers often fail to recurse into. Legitimate email never uses `<foreignObject>` — logos and data visualizations use pre-rendered images or plain SVG without embedded HTML. The presence of `<foreignObject>` anywhere in an email body is exclusively a sandbox-escape / sanitizer-bypass attempt. Weighted at +5, matching script-in-body, iframe-in-body, and inline-event-handler-in-body — all client-side-execution vectors.","tier":"danger","category":"body","isThin":false}}