You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently in places like the credential issuer logo as merged in openid/OpenID4VCI#170. The logo is permitted to be a URI which can being either a network resolvable reference like an https based URL or a data based URI. Furthermore it can be an image of a variety of formats such as an svg, png and or JPEG. Collectively these options represent a significant interoperability issue for implementations and a potential security issue due to the surface area of general purpose URI schemes like data URI's which have capability well beyond image encoding, such as allowing for encoding javascript which opens a potential risk around RCE.