rootpwn

critical · CVSS v3 9.9 · CVSS v4 9.4

CVE-2026-105080

ConvertX versions prior to 0.19.0 allow recipe files to be passed directly to Calibre's ebook-convert program, enabling execution of arbitra

Overview

ConvertX versions prior to 0.19.0 allow recipe files to be passed directly to Calibre's ebook-convert program, enabling execution of arbitrary code contained in .recipe or .downloaded_recipe files. This flaw can be exploited by attackers who supply malicious recipe files to a vulnerable ConvertX instance. The vulnerability is critical and can lead to full compromise of affected systems.

Description

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

Impact

The flaw violates confidentiality by allowing attackers to read sensitive data, integrity by enabling arbitrary code execution that can modify files or install malware, and availability by potentially crashing or disabling the conversion service. Administrators of systems that use ConvertX to process eBook recipes are directly impacted, as are end users who rely on those conversions for legitimate content.

Remediation

Upgrade ConvertX to version 0.19.0 or later where recipe files are properly blocked. If an upgrade is not immediately possible, disable or remove the recipe file handling feature, validate recipe files against a whitelist, and run ebook-convert in a sandboxed environment. Monitor logs for unexpected recipe file usage and apply system hardening to limit execution privileges.

Risk context

The CVSS v3 score of 9.9 and critical severity indicate a high urgency for remediation. With no EPSS data available, the risk remains significant for any environment still running vulnerable ConvertX versions.

Affected products

  • ConvertX
  • Calibre

Scores

Severity
critical
CVSS v2
9
CVSS v3
9.9
CVSS v4
9.4
EPSS
—

ConvertX Calibre recipe-file code-execution critical sandbox patch

← All CVEs