Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-4980

Опубликовано: 27 мар. 2026
Источник: debian
EPSS Низкий

Описание

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
inkscapefixed1.4-4package
inkscapenot-affectedbullseyepackage

Примечания

  • https://gitlab.com/inkscape/inkscape/-/work_items/3557

  • https://gitlab.com/inkscape/inkscape/-/merge_requests/5269

  • Fixed by: https://gitlab.com/inkscape/inkscape/-/commit/5b7e540900ebdfa6a5d6c5475193f5025160dbc5 (INKSCAPE_1_3)

EPSS

Процентиль: 8%
0.00027
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
12 дней назад

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.

CVSS3: 6.3
redhat
12 дней назад

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.

CVSS3: 6.3
nvd
12 дней назад

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.

CVSS3: 6.3
github
12 дней назад

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.

EPSS

Процентиль: 8%
0.00027
Низкий
Уязвимость CVE-2026-4980