Impact
Koodo Reader, version 2.3.0 and earlier, contains an injection flaw that enables node integration in subframes through the open‑book IPC handler. Unsanitized innerHTML rendering of EPUB chapter content allows an attacker to embed hidden iframes that gain Node.js API access, thereby permitting execution of arbitrary operating‑system commands under the victim’s user privileges. This flaw satisfies a remote code execution and is classified as CWE‑94.
Affected Systems
All installations of Koodo Reader running version 2.3.0 or older are affected. The issue is present regardless of operating system because the vulnerable IPC logic exists in the core renderer. The vulnerability was fixed in version 2.3.1; upgrading to that release or any newer version removes the exploit path and fully protects the system.
Risk and Exploitability
The CVSS score of 8.4 reflects a high severity vulnerability. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploit. The flaw is not listed in the CISA KEV catalog and no public exploits have been reported. The likely attack vector is local: an attacker must deliver a crafted EPUB file that the victim opens; once opened, the malicious content can execute commands with the application’s permissions, potentially compromising data and integrity for the user’s account.
OpenCVE Enrichment