CVE-2026-104983 PUBLISHED

Linux Mint Xreader PDF Attachment Saving ev-window.c g_file_get_child path traversal

Assigner: VulDB
Reserved: 02.10.2026 Published: 03.10.2026 Updated: 03.10.2026

A vulnerability has been found in Linux Mint Xreader up to 4.6.9. Impacted is the function g_file_get_child of the file shell/ev-window.c of the component PDF Attachment Saving Handler. Such manipulation of the argument attachment leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. One of the project maintainers closed this issue as "completed", because "EPUB support was removed from Xreader and reimplemented in Xepub". Code analysis indicates that this might be a misunderstanding of the situation.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor Linux Mint
Product Xreader
Versions
  • Version 4.6.0 is affected
  • Version 4.6.1 is affected
  • Version 4.6.2 is affected
  • Version 4.6.3 is affected
  • Version 4.6.4 is affected
  • Version 4.6.5 is affected
  • Version 4.6.6 is affected
  • Version 4.6.7 is affected
  • Version 4.6.8 is affected
  • Version 4.6.9 is affected

Credits

  • rodtvs (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Path Traversal CWE