CVE-2026-4980
Analyzed
Analyzed - Analysis Complete
Local File Disclosure in Inkscape XInclude via Malicious SVG
Publication date: 2026-03-27
Last updated on: 2026-05-26
Assigner: GitLab Inc.
Description
Description
A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| inkscape | inkscape | From 1.1 (inc) to 1.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-611 | The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. |