CVE-2026-105080: c4illin Convertx

Critical severity, CVSS 9.9. EPSS: 0.3% chance of exploitation in the next 30 days.

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

Affected products

  • c4illin Convertx: before 0.19.0 (fixed in 0.19.0)

Published 2026-10-03. Last modified 2026-10-06.