CVE-2026-4980
EUVD-2026-1665927.03.2026, 15:17
A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| inkscape | inkscape | 1.1 ≤ 𝑥 < 1.3 |
𝑥
= Vulnerable software versions