CRITICAL 9.9 CVE-2026-105080 Published 3 Oct 2026

ConvertX Calibre Recipe File Code Execution Vulnerability

Worried this affects your website?

In ConvertX before 0.19.0, a Calibre recipe file code execution vulnerability exists in converters/calibre.ts.

The converter does not block recipe files and instead passes them to the ebook-convert program from Calibre.

This affects executable code in a .recipe or .downloaded_recipe file.

Reference: CVE-2026-105080 on NVD

← Back to Security News