M9 section S2 — two real security fixes in notes.py: - Zip decompression bomb (issue #1980): note import read each zip entry with a whole-entry zf.read() and no cap, so a small archive could inflate to GBs and exhaust memory/disk. Add _ImportBudget — streams entries with a per-entry (64MB) and cumulative (512MB) decompressed cap, raising _ImportTooLarge past either; reject >10k entries up front; abort → 413 with the transaction rolled back. - SVG stored-XSS (issue #1981): attachment download served anything image/* inline, so an image/svg+xml attachment could execute script in-origin — and notes are shareable (rule 47), so this hit shared-note viewers. Inline now allowlists the trusted raster types only (png/jpeg/gif/webp); svg/html/xml/etc. download. Verified py_compile + ruff. Runtime (importing a bomb, opening an SVG) is operator-verified on deploy — no Postgres CI lane. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FRgehjoz7Yv8LkUfADxACm