Description

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.

INFO

Published Date :

2026-03-27T14:50:48.271Z

Last Modified :

2026-03-27T14:50:48.271Z

Source :

GitLab
AFFECTED PRODUCTS

The following products are affected by CVE-2026-4980 vulnerability.

No data.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact