Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108694

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Oct 11, 2026
Vendor unknown

Description

ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.

References