CVE-2026-4980: Inkscape
Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.
Affected products
- Inkscape Inkscape: from 1.1, before 1.3 (fixed in 1.3)
Published 2026-03-27. Last modified 2026-06-17.