CyberRota Analysis
AI-GeneratedKoodo Reader versions 2.3.0 and earlier are susceptible to remote code execution due to the open-book IPC handler allowing nodeIntegrationInSubFrames and rendering EPUB chapter content with unsanitized innerHTML. An attacker can exploit this vulnerability by crafting a malicious EPUB file that executes arbitrary commands on the victim's system with their privileges upon opening the file. Users and organizations utilizing Koodo Reader should prioritize upgrading to version 2.3.1 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files because the open-book IPC handler enables nodeIntegrationInSubFrames and EPUB chapter content is rendered with unsanitized innerHTML. An attacker can craft an EPUB book that, when imported and opened by the victim, instantiates a hidden iframe with Node.js API access and executes arbitrary operating system commands with the victim user's privileges. This issue is fixed in version 2.3.1.