
CVE-2026-4980 A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG fil… https://www.cve.org/CVERecord?id=CVE-2026-4980
Post summary
The statement discloses a local file disclosure flaw in Inkscape’s XInclude processing, enabling attackers to read local files through crafted SVGs; no PoC, exploit, patch or active exploitation evidence is presented.

