Arbitrary File Read Vulnerability in ConvertX Product from C4illin
CVE-2026-108694
7.1HIGH
What is CVE-2026-108694?
An arbitrary file read vulnerability exists in ConvertX up to version 0.19.0, allowing authenticated users to access sensitive server files. This issue arises because the application invokes the Pandoc converter without the necessary --sandbox flag. Consequently, attackers can exploit this flaw by uploading specially crafted reStructuredText documents containing absolute paths. After processing the files, they are able to download the contents of the specified server files, potentially exposing critical information.
Affected Version(s)
ConvertX 0 <= 0.19.0
