CyberRota Analysis
AI-GeneratedThe vulnerability in ConvertX allows unblocked recipe files to be processed by the ebook-convert program from Calibre, potentially executing arbitrary code contained within these files. This critical flaw poses a significant risk to users who handle recipe files, as it could lead to remote code execution on affected systems. Organizations using ConvertX, especially those handling untrusted recipe files, should prioritize immediate remediation to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.