Okay a tiny thread because people are going to freak out:
This exploit in particular takes advantage of a special command that renders images (via attribute escape). If you have an overlay that processes images (most don't) then yes, this is your problem.
Overlay must explicitly create img DOM.