Arbitrary File Read Vulnerability in ConvertX Product from C4illin
CVE-2026-108694

7.1HIGH

Key Information:

Vendor

C4illin

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108694?

An arbitrary file read vulnerability exists in ConvertX up to version 0.19.0, allowing authenticated users to access sensitive server files. This issue arises because the application invokes the Pandoc converter without the necessary --sandbox flag. Consequently, attackers can exploit this flaw by uploading specially crafted reStructuredText documents containing absolute paths. After processing the files, they are able to download the contents of the specified server files, potentially exposing critical information.

Affected Version(s)

ConvertX 0 <= 0.19.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.