Path Traversal Vulnerability in Linux Mint Xreader PDF Handler
CVE-2026-104983
Key Information:
- Vendor
Linux Mint
- Status
- Vendor
- CVE Published:
- 3 October 2026
Badges
What is CVE-2026-104983?
A path traversal vulnerability exists in the PDF Attachment Saving Handler of Linux Mint's Xreader up to version 4.6.9. This issue arises from improper handling of file paths in the g_file_get_child function, allowing malicious actors to manipulate attachment arguments and access unintended files on the server. This exploitation can occur remotely, posing serious risks to affected systems. While the maintainers have indicated the issue is resolved through the removal of EPUB support from Xreader, the potential for exploitation suggests that users should remain vigilant and ensure they are using the most updated version of the software.
Affected Version(s)
Xreader 4.6.0
Xreader 4.6.1
Xreader 4.6.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
