CVE-2026-105080
- EPSS 0.33%
- Veröffentlicht 03.10.2026 01:17:23
- Zuletzt bearbeitet 06.10.2026 17:17:16
In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.
CVE-2026-85618
- EPSS 0.38%
- Veröffentlicht 04.09.2026 14:32:10
- Zuletzt bearbeitet 10.09.2026 16:18:00
ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input directives. Attackers can upload .tex files containing \\input{path} or \\verbati...
CVE-2026-24741
- EPSS 0.41%
- Veröffentlicht 27.01.2026 21:11:57
- Zuletzt bearbeitet 12.02.2026 21:08:24
ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the `POST /delete` endpoint uses a user-controlled `filename` value to construct a filesystem path and deletes it via `unlink` without sufficient validation. By supplying pa...
CVE-2025-66449
- EPSS 0.77%
- Veröffentlicht 16.12.2025 00:10:49
- Zuletzt bearbeitet 07.10.2026 19:10:00
ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwriting binaries and allowing code execution. The upload function takes `file...