Do ereaders (that have a browser) and apps (all apps, any platform) that support Javascript need a setting that disables it? Or at least by default sandboxes if to only allow resources in the file? Or disable it always in an svg?
Javascript Trojans in svg images