CVE-2026-104983 | Linux Mint Xreader up to 4.6.9 PDF Attachment Saving shell/ev-window.c g_file_get_child attachment path traversal (Issue 714)
A vulnerability, which was classified as critical, was found in Linux Mint Xreader up to 4.6.9. Impacted is the function g_file_get_child of the file shell/ev-window.c of the component PDF Attachment Saving Handler. Such manipulation of the argument attachment leads to path traversal.
This vulnerability is listed as CVE-2026-104983. The attack may be performed from remote. In addition, an exploit is available.
One of the project maintainers closed this issue as “completed”, because “EPUB support was removed from Xreader and reimplemented in Xepub”. Code analysis indicates that this might be a misunderstanding of the situation.VulDB Recent EntriesRead More