Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 03 Oct 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Code Execution via Unvalidated Calibre Recipe Files |
Sat, 03 Oct 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file. | |
| First Time appeared |
C4illin
C4illin convertx |
|
| Weaknesses | CWE-829 | |
| CPEs | cpe:2.3:a:c4illin:convertx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
C4illin
C4illin convertx |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-06T16:45:47.103Z
Reserved: 2026-10-03T00:39:27.941Z
Link: CVE-2026-105080
Updated: 2026-10-06T16:45:43.047Z
Status : Deferred
Published: 2026-10-03T01:17:23.650
Modified: 2026-10-06T17:17:16.833
Link: CVE-2026-105080
No data.
OpenCVE Enrichment
Updated: 2026-10-03T03:30:19Z
-
CWE-829
Inclusion of Functionality from Untrusted Control Sphere