GHSA-r4xg-82px-pwx6HighCVSS 6.5

ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated...

Published
October 11, 2026
Last Modified
October 11, 2026

🔗 CVE IDs covered (1)

📋 Description

ConvertX through 0.19.0 contains an arbitrary file read vulnerability that allows authenticated users to read server files because src/converters/pandoc.ts invokes Pandoc without the --sandbox flag. Attackers can upload a reStructuredText document with an include directive naming an absolute path, convert it, and download output containing the referenced file's contents.

🔗 References (6)