Description
A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function setup_document_content_list/g_strdup_printf of the file backend/epub/epub-document.c of the component EPUB File Handler. This manipulation causes path traversal. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 4.6.6 is capable of addressing this issue. Patch name: a5aecea074e8564b7a22f1ce054b31ec862974b7. It is advisable to upgrade the affected component. One of the project maintainers explains, that "EPUB support was removed from Xreader and reimplemented in Xepub".
Published: 2026-10-03
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Directory Traversal
Action: Immediate Patch
AI Analysis

Impact

The flaw in Linux Mint Xreader, located in the EPUB file handler, allows an attacker to manipulate the file path processed by g_strdup_printf. This leads to a directory traversal vulnerability that can be exploited remotely. An attacker could craft a malicious EPUB file that, when opened by Xreader, causes the application to resolve file paths outside the intended directory, potentially reading or overwriting arbitrary files. The published exploit demonstrates how this weakness can be triggered, raising the potential for unauthorized file access and data theft.

Affected Systems

Linux Mint Xreader versions up to and including 4.6.5 are affected. The 4.6.6 release contains the fix. The vulnerability is present in the EPUB File Handler component that was removed and reimplemented in Xepub.

Risk and Exploitability

The CVSS score for this issue is 5.3, indicating moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA's KEV catalog. Because the attack vector is remote—an attacker can provide a crafted EPUB file—the exploitation process is straightforward. The publicly available exploit shows that a single malicious file is sufficient to trigger the path traversal, and no special privileges or additional conditions are required. Consequently, the vulnerability is considered moderately exploitable, especially on systems that routinely open or serve EPUB files to end users.

Generated by OpenCVE AI on October 3, 2026 at 09:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Linux Mint Xreader to version 4.6.6 or newer, which contains the patch for the EPUB file handler.
  • If an update cannot be performed promptly, uninstall or disable Xreader to remove the vulnerable component from the system.
  • Prevent delivery or opening of EPUB files from untrusted sources by using access controls or content filtering.
  • Configure the filesystem to restrict write permissions in directories where Xreader extracts EPUB content, limiting the impact of any path traversal that may still occur.

Generated by OpenCVE AI on October 3, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function setup_document_content_list/g_strdup_printf of the file backend/epub/epub-document.c of the component EPUB File Handler. This manipulation causes path traversal. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version 4.6.6 is capable of addressing this issue. Patch name: a5aecea074e8564b7a22f1ce054b31ec862974b7. It is advisable to upgrade the affected component. One of the project maintainers explains, that "EPUB support was removed from Xreader and reimplemented in Xepub".
Title Linux Mint Xreader EPUB File epub-document.c g_strdup_printf path traversal
First Time appeared Linux Mint
Linux Mint xreader
Weaknesses CWE-22
CPEs cpe:2.3:o:linux_mint:xreader:*:*:*:*:*:*:*:*
Vendors & Products Linux Mint
Linux Mint xreader
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Linux Mint Xreader
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-03T08:00:14.805Z

Reserved: 2026-10-02T18:33:00.512Z

Link: CVE-2026-104982

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T08:16:26.293

Modified: 2026-10-03T08:16:26.293

Link: CVE-2026-104982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T09:30:19Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')