Description
ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.
Published: 2026-10-11
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.
Title ConvertX through 0.19.0 Arbitrary File Read via Pandoc Converter
First Time appeared C4illin
C4illin convertx
Weaknesses CWE-73
CPEs cpe:2.3:a:c4illin:convertx:*:*:*:*:*:*:*:*
Vendors & Products C4illin
C4illin convertx
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

C4illin Convertx
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T01:35:44.264Z

Reserved: 2026-10-10T23:08:34.843Z

Link: CVE-2026-108694

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T02:16:37.777

Modified: 2026-10-11T02:16:37.777

Link: CVE-2026-108694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-73

    External Control of File Name or Path