CVE-2026-105080
Received Received - Intake

ConvertX Remote Code Execution via Unrestricted Recipe Files

Vulnerability report for CVE-2026-105080, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: MITRE

Description

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ConvertX before version 0.19.0 has a vulnerability where recipe files (with .recipe or .downloaded_recipe extensions) are not blocked and are passed to the ebook-convert program from Calibre. This allows executable code in these files to run, potentially leading to unauthorized actions or system compromise.

Detection Guidance

Check if ConvertX version is below 0.19.0 by running: convertx --version. Inspect recipe files (.recipe or .downloaded_recipe) in your system for executable code. Review logs for ebook-convert program calls from ConvertX.

Impact Analysis

This vulnerability could allow attackers to execute arbitrary code on your system if you process untrusted recipe files. It may lead to data breaches, system compromise, or unauthorized access to sensitive information. The high CVSS scores (9.4 v4.0, 9.9 v3.1) indicate severe impact.

Compliance Impact

This vulnerability could violate compliance requirements under GDPR and HIPAA by enabling unauthorized access to personal or health data. Organizations processing such data must ensure systems are patched to prevent breaches that could lead to regulatory penalties.

Mitigation Strategies

Upgrade ConvertX to version 0.19.0 or later. Remove or block .recipe and .downloaded_recipe files from processing. Monitor for unauthorized ebook-convert executions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105080. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart