Executable Code Execution Vulnerability in ConvertX by C4illin
CVE-2026-105080

9.4CRITICAL

Key Information:

Vendor

C4illin

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105080?

In ConvertX versions prior to 0.19.0, an oversight in the handling of recipe files allows these files to be passed unfiltered to the ebook-convert program from Calibre. This vulnerability may enable attackers to execute arbitrary code by leveraging executable code embedded within .recipe or .downloaded_recipe files, posing significant security risks to users.

Affected Version(s)

ConvertX 0 < 0.19.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.