CVE-2026-4980: Improper Restriction of XML External Entity Reference in Inkscape
Published Mar 27, 2026
·Updated
A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:include tags.
Affected Software
2 affected components
Inkscape Inkscape>=1.1<1.3
Inkscape Inkscape>=1.1<1.3
Remediation
Information
Upgrade to version 1.3 or above
Patch Available
Event History
Mar 27, 2026
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-4980?
CVE-2026-4980 has been rated as a medium severity vulnerability due to the local file disclosure potential.
2
How do I fix CVE-2026-4980?
To fix CVE-2026-4980, update Inkscape to version 1.3 or later.
3
What types of software are affected by CVE-2026-4980?
CVE-2026-4980 affects Inkscape versions 1.1 to 1.2.999 inclusive.
4
What does CVE-2026-4980 exploit?
CVE-2026-4980 exploits improper restriction of XML External Entity reference in the XInclude processing component.
5
Can a remote attacker exploit CVE-2026-4980?
Yes, a remote attacker can exploit CVE-2026-4980 to read local files on an affected system.