CVE-2019-7106

Executive Summary

Adobe XD 16.0 and earlier are vulnerable to a path traversal flaw that can be leveraged to read arbitrary files and execute code. An attacker can supply crafted file paths to bypass sandbox restrictions, enabling remote code execution on the victim’s machine. The vulnerability is not listed in CISA KEV, but it remains a high‑risk flaw for users who have not applied the latest updates.


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2019-05-23T16:29:08.917 - Last Modified: 2026-09-15T15:33:05.933

Original Description: Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.

"Do, or do not. There is no try."

— Yoda
Source: NVD