I will investigate, I suspect they do not support it (or it is turned off by default) as they don’t want to deal with the additional security workload.
Did you complete your investigation? Was it security-related, as you suspected? I think, but I am not certain, that Discourse applies a sanitizer to SVG files when their upload is allowed.