critical · CVSS v3 9.9 · CVSS v4 9.4
CVE-2026-105080
ConvertX versions prior to 0.19.0 allow recipe files to be passed directly to Calibre's ebook-convert program, enabling execution of arbitra
Overview
ConvertX versions prior to 0.19.0 allow recipe files to be passed directly to Calibre's ebook-convert program, enabling execution of arbitrary code contained in .recipe or .downloaded_recipe files. This flaw can be exploited by attackers who supply malicious recipe files to a vulnerable ConvertX instance. The vulnerability is critical and can lead to full compromise of affected systems.
Description
In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.
Impact
The flaw violates confidentiality by allowing attackers to read sensitive data, integrity by enabling arbitrary code execution that can modify files or install malware, and availability by potentially crashing or disabling the conversion service. Administrators of systems that use ConvertX to process eBook recipes are directly impacted, as are end users who rely on those conversions for legitimate content.
Remediation
Upgrade ConvertX to version 0.19.0 or later where recipe files are properly blocked. If an upgrade is not immediately possible, disable or remove the recipe file handling feature, validate recipe files against a whitelist, and run ebook-convert in a sandboxed environment. Monitor logs for unexpected recipe file usage and apply system hardening to limit execution privileges.
Risk context
The CVSS v3 score of 9.9 and critical severity indicate a high urgency for remediation. With no EPSS data available, the risk remains significant for any environment still running vulnerable ConvertX versions.
Affected products
- ConvertX
- Calibre
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 9.9
- CVSS v4
- 9.4
- EPSS
- —