CVE-2026-104983
Received Received - Intake

Path Traversal in Linux Mint Xreader PDF Handler

Vulnerability report for CVE-2026-104983, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: VulDB

Description

A vulnerability has been found in Linux Mint Xreader up to 4.6.9. Impacted is the function g_file_get_child of the file shell/ev-window.c of the component PDF Attachment Saving Handler. Such manipulation of the argument attachment leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. One of the project maintainers closed this issue as "completed", because "EPUB support was removed from Xreader and reimplemented in Xepub". Code analysis indicates that this might be a misunderstanding of the situation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
linux_mint xreader to 4.6.9 (inc)
linuxmint xreader to 4.6.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in Linux Mint Xreader up to version 4.6.9. It occurs in the PDF Attachment Saving Handler where the function g_file_get_child in shell/ev-window.c improperly handles the attachment argument. This allows manipulation of file paths, enabling an attacker to save files to unintended locations on the system.

Detection Guidance

Check Xreader version with 'xreader --version' or 'dpkg -l xreader'. If version is 4.6.9 or below, the system is vulnerable. Inspect PDF attachments for filenames containing '../' sequences which may indicate path traversal attempts.

Impact Analysis

An attacker could exploit this to write malicious files like .desktop files to specific locations. When a user double-clicks such a file, it could lead to arbitrary code execution. The attack requires minimal user interaction: opening a malicious PDF, right-clicking an attachment, selecting Save As, and choosing a directory.

Compliance Impact

This vulnerability allows attackers to write files to arbitrary locations on the filesystem by exploiting path traversal in PDF attachment saving. This could lead to unauthorized data access, modification, or execution of malicious files, which may violate GDPR's data integrity and confidentiality requirements or HIPAA's safeguards for protected health information.

Mitigation Strategies

Upgrade Xreader to the latest version or remove EPUB support if using version 4.6.9 or below. Avoid opening PDFs from untrusted sources. Disable automatic PDF attachment handling in Xreader settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104983. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart