AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-55408

HIGH · CVSS 8.4 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

Koodo Reader versions 2.3.0 and earlier are susceptible to remote code execution due to the open-book IPC handler allowing nodeIntegrationInSubFrames and rendering EPUB chapter content with unsanitized innerHTML. An attacker can exploit this vulnerability by crafting a malicious EPUB file that executes arbitrary commands on the victim's system with their privileges upon opening the file. Users and organizations utilizing Koodo Reader should prioritize upgrading to version 2.3.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55408
Severity
HIGH
CVSS
8.4
EPSS
0.19%

Original NVD Description

Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files because the open-book IPC handler enables nodeIntegrationInSubFrames and EPUB chapter content is rendered with unsanitized innerHTML. An attacker can craft an EPUB book that, when imported and opened by the victim, instantiates a hidden iframe with Node.js API access and executes arbitrary operating system commands with the victim user's privileges. This issue is fixed in version 2.3.1.