CVE-2026-105080

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-03: 210-03
Referenced assets2 URLs
Full discourse2 posts
  • VulnTracker@vuln_tracker

    CVE-2026-105080 hits C4illin's ConvertX, CVSS 9.9. It passes uploaded .recipe and .downloaded_recipe files straight to Calibre's ebook-convert program without blocking them, and in Calibre those files are executable code, not just data. VulnTracker recommends upgrading to ConvertX 0.19.0 now, this is code execution from a normal file conversion. http://vulntracker.io/cves/CVE-2026-105080 #ConvertX #CVE #InfoSec

    00032258
    793 followersView on X
  • PJ@Npj8448

    CVE-2026-105080 — CTIWatch · 24h digest #ThreatIntel #CyberSecurity https://pranithjain.qzz.io/threatintel/predictive/global-pulse

    0000035
    80 followersView on X

Explore more