
CVE-2026-105080 hits C4illin's ConvertX, CVSS 9.9. It passes uploaded .recipe and .downloaded_recipe files straight to Calibre's ebook-convert program without blocking them, and in Calibre those files are executable code, not just data. VulnTracker recommends upgrading to ConvertX 0.19.0 now, this is code execution from a normal file conversion. http://vulntracker.io/cves/CVE-2026-105080 #ConvertX #CVE #InfoSec

