CVE-2026-85618: c4illin Convertx
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input directives. Attackers can upload .tex files containing \\input{path} or \\verbatiminput{path} directives to have the TeX engine read arbitrary files accessible to the server process and include them in downloadable PDF output.
Affected products
- c4illin Convertx: up to and including 0.18.0
Published 2026-09-04. Last modified 2026-09-10.