Skip to main content
Vulnerability Database/CVE-2026-105080

CVE-2026-105080: ConvertX RCE Vulnerability via Calibre

CVE-2026-105080 is a remote code execution vulnerability in ConvertX before version 0.19.0 that allows attackers to execute arbitrary code through malicious recipe files. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-105080 Overview

ConvertX, an open-source self-hosted file conversion application, contains an arbitrary code execution vulnerability in versions prior to 0.19.0. The converters/calibre.ts module accepts .recipe and .downloaded_recipe files and forwards them to the Calibre ebook-convert program. Calibre recipe files are Python scripts, so passing attacker-controlled recipes to ebook-convert enables execution of arbitrary code on the server hosting ConvertX. The flaw is tracked as CWE-829: Inclusion of Functionality from Untrusted Control Sphere.

Critical Impact

An authenticated ConvertX user can upload a crafted recipe file to achieve arbitrary code execution in the ConvertX process context.

Affected Products

  • ConvertX versions prior to 0.19.0
  • The converters/calibre.ts conversion handler
  • Deployments integrating Calibre ebook-convert through ConvertX

Discovery Timeline

  • 2026-10-03 - CVE-2026-105080 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-105080

Vulnerability Analysis

ConvertX wraps Calibre's ebook-convert command to transform user-uploaded documents between formats. The calibre.ts converter module declared supported extensions including recipe, which allowed .recipe and .downloaded_recipe files to pass validation. Calibre treats recipe files as executable Python modules that fetch and format content for ebook generation. Submitting a recipe file through ConvertX therefore causes ebook-convert to execute attacker-controlled Python code on the host.

The attacker needs the ability to submit a conversion job, which typically requires a ConvertX account. Once code executes, the attacker inherits the privileges of the ConvertX runtime user and can access local files, outbound network paths, and any mounted conversion directories.

Root Cause

The root cause is an allowlist that failed to distinguish between inert document formats and executable Calibre recipe formats. By including recipe alongside benign formats such as txt, rtf, and pml, ConvertX implicitly treated untrusted scripts as data. This matches the pattern described by [CWE-829], where functionality from an untrusted control sphere is incorporated without sufficient isolation.

Attack Vector

Exploitation requires network reach to the ConvertX web interface and the privileges needed to initiate a conversion. The attacker uploads a .recipe or .downloaded_recipe file whose Python payload runs when ebook-convert processes it. No memory corruption, sandbox escape, or additional vulnerability chain is needed.

typescript
// Patch excerpt from src/converters/calibre.ts
// Source: https://github.com/C4illin/ConvertX/commit/0ca17dad7fa65e2e34823b59b95dd00bb1066b66
       "pml",
       "rb",
       "rtf",
-      "recipe",
       "snb",
       "tcr",
       "txt",

The fix removes recipe from the list of accepted input extensions so Calibre never receives executable recipe files from ConvertX.

Detection Methods for CVE-2026-105080

Indicators of Compromise

  • Uploaded files with .recipe or .downloaded_recipe extensions in ConvertX input or temporary directories.
  • ebook-convert child processes spawned with recipe inputs and unexpected outbound network connections.
  • New files, cron entries, or shell history created by the ConvertX runtime user following a conversion job.

Detection Strategies

  • Inspect ConvertX access and job logs for conversion requests referencing recipe file extensions.
  • Monitor process execution telemetry for ebook-convert invocations whose arguments reference recipe files.
  • Alert on child processes of the ConvertX service that are not standard conversion binaries, such as sh, bash, python, or curl.

Monitoring Recommendations

  • Forward process, file, and network telemetry from ConvertX hosts to a central analytics platform for correlation.
  • Baseline normal ebook-convert behavior and flag deviations such as outbound DNS or HTTP from the conversion process.
  • Retain web request logs long enough to reconstruct the sequence of uploads leading to any suspicious execution.

How to Mitigate CVE-2026-105080

Immediate Actions Required

  • Upgrade ConvertX to version 0.19.0 or later, which removes recipe from the Calibre converter allowlist.
  • Audit existing ConvertX storage for .recipe and .downloaded_recipe files and quarantine any that are present.
  • Rotate credentials and secrets accessible to the ConvertX runtime user if exploitation is suspected.

Patch Information

The fix is delivered in the ConvertX v0.19.0 release via commit 0ca17da. See the GitHub Security Advisory GHSA-m4hh-rqmf-c8hw for the vendor's description of the issue.

Workarounds

  • Restrict ConvertX account creation and require authentication for all conversion endpoints until patched.
  • Place ConvertX behind a reverse proxy that rejects uploads with .recipe or .downloaded_recipe extensions.
  • Run the ConvertX container as an unprivileged user with no outbound network access to limit post-exploitation impact.
bash
# Example reverse proxy filter and container upgrade
# Nginx: block recipe uploads before they reach ConvertX
if ($request_uri ~* "\.(recipe|downloaded_recipe)(\?|$)") {
    return 403;
}

# Docker: pull and run the patched release
docker pull ghcr.io/c4illin/convertx:v0.19.0
docker stop convertx && docker rm convertx
docker run -d --name convertx \
  --user 1000:1000 \
  -p 3000:3000 \
  -v /srv/convertx/data:/app/data \
  ghcr.io/c4illin/convertx:v0.19.0

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.