Sceawere

Vulnerability Detail

CVE-2026-104983UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Xreader PDF Attachment Path Traversal

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
4h ago
Vendor
Linux Mint
Product
Xreader
Attack Type
Path Traversal
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in Linux Mint Xreader up to 4.6.9. Impacted is the function g_file_get_child of the file shell/ev-window.c of the component PDF Attachment Saving Handler. Such manipulation of the argument attachment leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. One of the project maintainers closed this issue as "completed", because "EPUB support was removed from Xreader and reimplemented in Xepub". Code analysis indicates that this might be a misunderstanding of the situation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-03T11:17:33.473Z",
  "pubdate": "2026-10-03T11:17:33.473Z",
  "executiveSummary": "A path traversal vulnerability exists in Linux Mint Xreader up to version 4.6.9 within the PDF Attachment Saving Handler.\nThe flaw originates from improper validation of input parameters in the g_file_get_child function located in shell/ev-window.c.\nA remote attacker can leverage this vulnerability to escape the intended directory constraints when saving attachments, potentially allowing for arbitrary file write or overwrite operations on the host filesystem.\nThe risk is significant as the exploit is publicly disclosed, increasing the likelihood of malicious exploitation.\nDespite project maintainers suggesting the removal of EPUB support as a resolution, code analysis indicates that the vulnerability persists within the PDF attachment handling logic, meaning existing installations remain fully exposed to this attack vector.\nNo specific authentication is required to trigger the path traversal, and the attack can be initiated remotely, provided the user interacts with a crafted PDF document.",
  "technicalDetails": "The vulnerability resides in the PDF Attachment Saving Handler of Linux Mint Xreader, specifically within the g_file_get_child function inside the shell/ev-window.c source file.\nThe root cause is the insecure handling of the 'attachment' argument, which fails to sanitize or validate input against directory traversal sequences such as '../'.\nWhen a user triggers the saving of a document attachment, the application constructs a target file path by concatenating a user-provided or metadata-derived filename with a base directory using g_file_get_child.\nBecause the input is not checked for traversal characters, an attacker can craft a malicious PDF document where the attachment metadata includes path traversal sequences (e.g., '../../../../home/user/.bashrc').\nUpon attempting to save the attachment, the application resolves the path outside of the designated destination directory, enabling the attacker to write files to arbitrary locations accessible with the privileges of the user running Xreader.\nThe attack flow involves the following steps: 1. The attacker embeds a malicious attachment entry within a PDF file structure. 2. The attacker modifies the metadata associated with the attachment filename to include arbitrary directory navigation sequences. 3. The victim opens the malicious PDF file using an affected version of Xreader. 4. When the victim initiates a 'Save Attachment' action, the application processes the tainted filename, resulting in the file being written to a location controlled by the attacker via path traversal.\nThis vulnerability is classified as a remote attack vector, as the malicious document can be distributed via email, file sharing, or web downloads. There are no authentication requirements for the attacker to successfully construct the exploit, and the requirement for user interaction (triggering the save action) makes it a practical target for social engineering campaigns.\nThe impact of a successful exploitation includes arbitrary file write, which can lead to code execution if an attacker can overwrite configuration files, scripts, or binary files that the user or system subsequently executes. The maintainer's note regarding the removal of EPUB support is technically insufficient as a remediation because the vulnerability is specifically identified within the PDF handling component, which remains active in the codebase."
}
CVE-2026-104983: Xreader PDF Attachment Path Traversal (MEDIUM Severity, CVSS: 6.3) | Sceawere