Home

Description

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.

PUBLISHED Reserved 2026-03-27 | Published 2026-03-27 | Updated 2026-04-06 | Assigner GitLab




MEDIUM: 6.3CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Problem types

CWE-611: Improper Restriction of XML External Entity Reference

Product status

Default status
unaffected

1.1 (semver) before 1.3
affected

Credits

VK (previously elttam) https://github.com/me0wday finder

References

gitlab.com/inkscape/inkscape/-/work_items/3557

gitlab.com/inkscape/inkscape/-/merge_requests/5269

cve.org (CVE-2026-4980)

nvd.nist.gov (CVE-2026-4980)

Download JSON