PT-2026-28702 · Inkscape+2 · Inkscape

Jeremy Stashewsky

·

Published

2026-03-27

·

Updated

2026-05-26

·

CVE-2026-4980

CVSS v3.1

6.3

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Inkscape versions 1.1 through 1.2
Description A local file disclosure issue exists in the XInclude processing component. A remote attacker can read local files by using a specially crafted SVG file that contains malicious xi:include tags.
Recommendations Update to version 1.3.

Exploit

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2026-4980

Affected Products

Inkscape