ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.

Project Subscriptions

Vendors Products
C4illin Subscribe
Convertx Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 11 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.
Title ConvertX through 0.19.0 Arbitrary File Read via Pandoc Converter
First Time appeared C4illin
C4illin convertx
Weaknesses CWE-73
CPEs cpe:2.3:a:c4illin:convertx:*:*:*:*:*:*:*:*
Vendors & Products C4illin
C4illin convertx
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T01:35:44.264Z

Reserved: 2026-10-10T23:08:34.843Z

Link: CVE-2026-108694

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T02:16:37.777

Modified: 2026-10-11T02:16:37.777

Link: CVE-2026-108694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T03:15:08Z

Weaknesses