Junglewise Threat Intelligence

CVE-2026-4980: Inkscape local file disclosure in XInclude processing

CVE-2026-4980 · Severity: medium · CVSS 6.3 · Published 2026-03-27

Executive brief

Inkscape is a popular open-source vector graphics editor used for creating and editing illustrations and diagrams. A vulnerability in how the software handles certain XML tags allows a malicious SVG file to automatically include and display the contents of private files from the user's computer. If a user opens a specially crafted file or uses Inkscape's command-line tools to process it, sensitive information like system passwords or private credentials could be exposed to an attacker.

Technical details

A XML External Entity (XXE) related vulnerability exists in Inkscape's XInclude processing component. The software improperly restricts XML External Entity references, specifically allowing the 'xi:include' tag to reference local file system paths (e.g., file:///etc/passwd) when parsing SVG files. An attacker can exploit this by providing a crafted SVG file that, when rendered or exported (e.g., to PDF via CLI), embeds the contents of local files into the output document. The vulnerability affects versions 1.1 through 1.2.x and was addressed in version 1.3 by limiting XInclude processing to internal shortcut configuration files only.

Affected products

  • Inkscape Inkscape 1.1 to 1.2.x (before 1.3)

Timeline

  • 2023-05-03: patched: Initial patch submitted via merge request 5269
  • 2026-03-27: disclosed: CVE published to NVD

References