PatchSiren cyber security CVE debrief
CVE-2026-4980 Inkscape CVE debrief
A local file disclosure vulnerability exists in Inkscape's XInclude processing component. Versions 1.1 through 1.2.x are affected. The vulnerability allows a remote attacker to read local files when a user opens a crafted SVG file containing malicious xi:include tags. The issue stems from improper handling of XML External Entity (XEE) processing via XInclude, classified under CWE-611 (Improper Restriction of XML External Entity Reference). The vulnerability was published on March 27, 2026, with the record last modified on May 26, 2026. A patch is available via merge request.
- Vendor
- Inkscape
- Product
- Unknown
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-27
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-03-27
- Advisory updated
- 2026-05-26
Who should care
Organizations and individuals using Inkscape versions 1.1 through 1.2.x for SVG editing, particularly those handling SVG files from untrusted sources. Security teams responsible for endpoint protection and software asset management should prioritize patching.
Technical summary
The vulnerability resides in Inkscape's XInclude processing implementation. When parsing SVG files containing xi:include elements, the application fails to properly restrict XML external entity resolution, allowing inclusion of arbitrary local files. The attack requires user interaction (opening a malicious SVG file) but can result in high confidentiality impact through local file disclosure. The attack surface is local (AV:L) with low attack complexity (AC:L), requiring no privileges (PR:N) but user interaction (UI:R). Scope is changed (S:C) due to the security impact extending beyond the vulnerable component to the underlying file system.
Defensive priority
medium
Recommended defensive actions
- Upgrade Inkscape to version 1.3 or later to remediate this vulnerability
- Review and apply the patch from the vendor's merge request if immediate upgrade is not feasible
- Implement security awareness training for users regarding risks of opening untrusted SVG files from unknown sources
- Consider disabling automatic file opening for SVG attachments in email clients and web browsers
- Monitor for suspicious SVG file handling in endpoint detection and response (EDR) solutions
Evidence notes
Vulnerability affects Inkscape versions 1.1 before 1.3. CVSS 3.1 vector: AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N. CPE criteria confirms version range. Patch available in GitLab merge request 5269. Exploit details tracked in GitLab work item 3557.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-4980 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-4980
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-4980 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4980
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://gitlab.com/inkscape/inkscape/-/merge_requests/5269
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://gitlab.com/inkscape/inkscape/-/work_items/3557
[email protected] - Exploit, Issue Tracking
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.