External risk intelligence

ConvertX Recipe File Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-105080

ConvertX is a tool for document conversion that processes recipe files. While it may be used in web-based document processing pipelines that are internet-facing, it is not inherently designed as an edge service or public gateway. Exposure depends heavily on the specific implementation of the software in a given environment.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts the ConvertX software, which handles document conversions. The issue allows specially crafted recipe files to execute arbitrary code, posing a significant security risk if not properly managed. The primary concern is to confirm if this specific software is in use and assess any potential exposure.

  • Unchecked files in document conversion can run malicious code.
  • It affects a tool used for document conversion processes.
  • Confirm usage and assess potential exposure is key.

Attack Path

How an attacker could exploit the issue

An attacker with low privileges can send a specially crafted recipe file to the ConvertX application. ConvertX, when processing this file, does not properly validate it and instead passes it to the underlying ebook-convert program. This allows an attacker to execute arbitrary code on the system hosting the ConvertX application.

  • Requires low-privilege access.
  • Processed recipe files trigger vulnerability.
  • Allows arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, executable code within recipe files could be affected, potentially impacting the behavior of the ConvertX application.

  • Executable code in recipe files.
  • Unblocked recipe files passed to ebook-convert.
  • Compromised application and system behavior.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in ConvertX allows for executable code execution via crafted recipe files, posing a critical risk. Application owners or platform teams responsible for the ConvertX deployment should be the first to act. The immediate priority is to identify all instances of ConvertX, confirm their exposure and business criticality, and locate the accountable owner for remediation planning.

  • Identify ConvertX instances and assess reachability.
  • Confirm asset ownership and business criticality.
  • Plan remediation based on exposure and risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is ConvertX?

ConvertX is a utility designed to automate document and ebook conversions. It typically functions as a backend processing engine that takes various input formats and transforms them into different digital book files by leveraging existing tools like Calibre's ebook-convert program.

What does CWE-829 mean for CVE-2026-105080?

CWE-829 refers to the inclusion of functionality from an untrusted control sphere. In the context of CVE-2026-105080, it means the application mistakenly trusts and executes instructions contained within user-supplied recipe files. Because the software fails to filter these files, it unknowingly hands off malicious commands to the underlying conversion tool, which then runs them with the application's permissions.

How is this vulnerability triggered?

The flaw is triggered when the application processes a specially crafted .recipe or .downloaded_recipe file. It is important to note that simply storing or having these files on a disk does not trigger the bug; the vulnerability only occurs when the conversion service actively attempts to process or parse a malicious file using the compromised component.

Do I need to worry if ConvertX is internal?

Halo Surface Signal indicates that while ConvertX is not inherently a public gateway, its risk profile changes based on your architecture. If your deployment uses ConvertX in an internet-facing document processing pipeline, it is more accessible to external threats. If the software is strictly limited to internal, isolated networks, the immediate reachability for an attacker is significantly lower.

When should I begin remediation for this issue?

You should begin by identifying every instance of ConvertX running within your environment. Once you have mapped your assets and confirmed which systems use this software, prioritize those that are most exposed to user-provided input. Finally, coordinate with the technical teams managing those specific servers to plan an upgrade to version 0.19.0 or higher.

References