OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105080

CRITICAL · CVSS 9.9 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-03 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability in ConvertX allows unblocked recipe files to be processed by the ebook-convert program from Calibre, potentially executing arbitrary code contained within these files. This critical flaw poses a significant risk to users who handle recipe files, as it could lead to remote code execution on affected systems. Organizations using ConvertX, especially those handling untrusted recipe files, should prioritize immediate remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105080
Severity
CRITICAL
CVSS
9.9
EPSS
0.33%

Original NVD Description

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.