Description
ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 11 Oct 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents. | |
| Title | ConvertX through 0.19.0 Arbitrary File Read via Pandoc Converter | |
| First Time appeared |
C4illin
C4illin convertx |
|
| Weaknesses | CWE-73 | |
| CPEs | cpe:2.3:a:c4illin:convertx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
C4illin
C4illin convertx |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T01:35:44.264Z
Reserved: 2026-10-10T23:08:34.843Z
Link: CVE-2026-108694
No data.
Status : Received
Published: 2026-10-11T02:16:37.777
Modified: 2026-10-11T02:16:37.777
Link: CVE-2026-108694
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-73
External Control of File Name or Path