Sceawere

Vulnerability Detail

CVE-2026-104982UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Xreader EPUB Path Traversal Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
2h ago
Vendor
Linux Mint
Product
Xreader
Attack Type
Path Traversal
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function setup_document_content_list/g_strdup_printf of the file backend/epub/epub-document.c of the component EPUB File Handler. This manipulation causes path traversal. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 4.6.6 is capable of addressing this issue. Patch name: a5aecea074e8564b7a22f1ce054b31ec862974b7. It is advisable to upgrade the affected component. One of the project maintainers explains, that "EPUB support was removed from Xreader and reimplemented in Xepub".

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-03T08:16:26.293Z",
  "pubdate": "2026-10-03T08:16:26.293Z",
  "executiveSummary": "A critical path traversal vulnerability exists in Linux Mint Xreader versions up to 4.6.5 within the EPUB File Handler component.\nThe flaw stems from improper input sanitization during the processing of EPUB document structures, specifically within the setup_document_content_list function.\nSuccessful exploitation allows a remote attacker to bypass intended file system boundaries, potentially accessing arbitrary files on the underlying system with the privileges of the Xreader application.\nThis vulnerability is exacerbated by the availability of public exploit code, increasing the risk of active exploitation.\nThe threat is particularly significant because it permits remote, unauthenticated access to sensitive data, necessitating immediate defensive action.\nAs a result of this security defect, the project maintainers have deprecated native EPUB support within Xreader, offloading the functionality to Xepub, and have issued a patch to address the underlying logic error.",
  "technicalDetails": "The vulnerability is located in backend/epub/epub-document.c, specifically within the setup_document_content_list function. The root cause is the insecure utilization of g_strdup_printf to construct file paths derived from the contents of the EPUB file package.\nEPUB files are essentially archives containing a collection of XML documents, images, and other media linked by an Open Container Format (OCF) specification. The application fails to adequately sanitize file path references defined within the OPF (Open Packaging Format) metadata or manifest.\nDuring the parsing process, an attacker can craft a malicious EPUB file where path references utilize traversal sequences, such as '../', to point to files outside the intended working directory of the document handler. Because g_strdup_printf does not perform inherent path normalization or validation, these malicious paths are interpreted literally by the application when it attempts to load or render document resources.\nThe attack flow follows a predictable pattern: 1) The attacker constructs a malicious EPUB archive containing an OCF document that references external system files through directory traversal vectors. 2) The attacker lures a victim to open this malicious document in an affected version of Xreader. 3) Upon opening the file, the EPUB File Handler invokes setup_document_content_list. 4) The vulnerable function processes the malicious path strings, concatenating them with base directories without sanitizing the traversal sequences. 5) The application subsequently attempts to read or display the content of the target file, effectively granting the attacker unauthorized access to sensitive local files.\nThis vulnerability allows for remote exploitation, as the malicious document can be delivered via common vectors like email or web downloads. There are no authentication requirements for this exploit, as the vulnerability is triggered automatically upon document ingestion and processing. The impact of post-exploitation activity is limited by the execution context of the Xreader process, but it remains a severe risk for potential information disclosure of sensitive configuration files, user data, or credentials stored on the local filesystem.\nThe maintainers have addressed this by introducing patch a5aecea074e8564b7a22f1ce054b31ec862974b7 and have effectively removed EPUB support from the core Xreader codebase in favor of Xepub, acknowledging the structural complexity and inherent security risks associated with parsing untrusted EPUB document packages."
}