CVE-2026-4980
EUVD-2026-1665927.03.2026, 15:17
A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| inkscape | inkscape | 1.1 ≤ 𝑥 < 1.3 | CNA |
Debian Releases