CVE-2019-7105
Executive Summary
Adobe XD versions 16.0 and earlier are vulnerable to a path traversal flaw (CVE‑2019‑7105) that allows attackers to read arbitrary files and ultimately execute code on the affected system. The vulnerability can be exploited remotely by supplying crafted file paths, leading to full compromise of the user’s environment. No current CISA KEV listing, but the risk remains significant for organizations still running legacy Adobe XD installations.
Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2019-05-23T16:29:08.887 - Last Modified: 2026-09-15T15:33:14.803
Original Description: Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.
"Accept challenges, so that you may feel the exhilaration of victory."
— George Patton