๐Ÿ” CVE Alert

CVE-2026-104982

MEDIUM 4.3

Linux Mint Xreader EPUB File epub-document.c g_strdup_printf path traversal

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function setup_document_content_list/g_strdup_printf of the file backend/epub/epub-document.c of the component EPUB File Handler. This manipulation causes path traversal. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 4.6.6 is capable of addressing this issue. Patch name: a5aecea074e8564b7a22f1ce054b31ec862974b7. It is advisable to upgrade the affected component. One of the project maintainers explains, that "EPUB support was removed from Xreader and reimplemented in Xepub".

CWE CWE-22
Vendor linux mint
Product xreader
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for linux mint xreader

Be the first to know when new medium vulnerabilities affecting linux mint xreader are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux Mint / Xreader
4.6.0 4.6.1 4.6.2 4.6.3 4.6.4 4.6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/413198 vuldb.com: https://vuldb.com/vuln/413198/cti vuldb.com: https://vuldb.com/cve/CVE-2026-104982 vuldb.com: https://vuldb.com/submit/964347 github.com: https://github.com/linuxmint/xreader/issues/713 gist.github.com: https://gist.github.com/rodtvs/63a34e7b20a9f97a1a7167a8a1db49c2 github.com: https://github.com/linuxmint/xreader/commit/a5aecea074e8564b7a22f1ce054b31ec862974b7 github.com: https://github.com/linuxmint/xreader/releases/tag/4.6.6

Credits

๐Ÿ” rodtvs (VulDB User) VulDB CNA Team