CVE-2026-108694
Received Received - Intake

Authenticated File Read in ConvertX via Pandoc Sandbox Bypass

Vulnerability report for CVE-2026-108694, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
C4illin ConvertX 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ConvertX through version 0.19.0 has an arbitrary file read vulnerability because it uses Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive pointing to an absolute path, convert it, and download output containing the referenced file's contents.

Detection Guidance

Check if ConvertX is running without the --sandbox flag in Pandoc commands. Inspect the pandoc.ts file in the ConvertX source code for the absence of --sandbox in the command construction. Look for unusual file reads in server logs, especially after users upload reStructuredText files with absolute path include directives.

Impact Analysis

This vulnerability allows authenticated users to read sensitive server files such as configuration files, application source code, database files, or other users' files. Confidentiality is breached as attackers can access restricted data on the system.

Compliance Impact

This vulnerability can lead to non-compliance with GDPR and HIPAA by exposing sensitive personal or health data. GDPR requires protecting personal data, while HIPAA mandates safeguarding protected health information. A breach could result in legal penalties and loss of trust.

Mitigation Strategies

Update ConvertX to a patched version that includes the --sandbox flag in Pandoc commands. If no patch is available, manually edit src/converters/pandoc.ts to add --sandbox to the Pandoc argument list. Restrict file permissions to limit access to sensitive files. Monitor for unauthorized file access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108694. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart