This seems like a tough task because SVG is quite large. When SVG is loaded as the top document, we use the XML parser which is more general than the html parser and seems even more difficult to guard against (e.g., ENTITY references).
For example, this is an unsafe svg file:
We can base64 encode this as an image, then put that image back into svg and it will be sandboxed:
<svg xmlns="
http://www.w3.org/2000/svg" xmlns:xlink="
http://www.w3.org/1999/xlink" width="100" height="100">
<image width="100%" height="100%" xlink:href=""></image>
</svg>