ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents. | |
| Title | ConvertX through 0.19.0 Arbitrary File Read via Pandoc Converter | |
| First Time appeared |
C4illin
C4illin convertx |
|
| Weaknesses | CWE-73 | |
| CPEs | cpe:2.3:a:c4illin:convertx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
C4illin
C4illin convertx |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T01:35:44.264Z
Reserved: 2026-10-10T23:08:34.843Z
Link: CVE-2026-108694
No data.
Status : Received
Published: 2026-10-11T02:16:37.777
Modified: 2026-10-11T02:16:37.777
Link: CVE-2026-108694
No data.
OpenCVE Enrichment
Updated: 2026-10-11T03:15:08Z
Weaknesses