https://seclists.org/oss-sec/2026/q2/606: Evince/Atril/Xader command injection CVE-2026-46529
Published May 19, 2026
·Updated
Affected Software
4 affected components
Gnome Evince<48.2
MATE Atril<1.28.4, <1.26.3
Linux Mint Xreader<4.6.4, <3.6.7
Gnome Papers
Frequently Asked Questions
1
What is the severity of CVE-2026-46529?
CVE-2026-46529 is classified as a high severity command injection vulnerability.
2
How do I fix CVE-2026-46529?
To fix CVE-2026-46529, update to Evince 48.2, Atril 1.28.4 or 1.26.3, or Xreader 4.6.4 or 3.6.7.
3
Which applications are affected by CVE-2026-46529?
CVE-2026-46529 affects Evince, Atril, and Xreader applications.
4
What is the cause of CVE-2026-46529?
CVE-2026-46529 is caused by missing quoting of shell-like input in the ev_spawn() function.
5
When was CVE-2026-46529 published?
CVE-2026-46529 was published on May 19, 2026.