PatchSiren cyber security CVE debrief
CVE-2026-108694 C4illin CVE debrief
CVE-2026-108694 is a high-severity vulnerability in ConvertX, a product by C4illin, which allows authenticated users to read arbitrary server files. The vulnerability exists because the Pandoc converter in ConvertX does not use the --sandbox flag, enabling attackers to exploit this weakness by uploading a specially crafted reStructuredText document with an include directive pointing to an absolute path on the server. This can lead to unauthorized access to sensitive server files.
- Vendor
- C4illin
- Product
- ConvertX
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
System administrators and security teams responsible for ConvertX installations, especially those using version 0.19.0 or earlier, should assess their exposure and take necessary actions to mitigate the risk. This includes verifying the version of ConvertX in use, restricting access to sensitive files, and monitoring for suspicious activities that could indicate exploitation attempts.
Why it matters
CVE-2026-108694 is a high-severity vulnerability in ConvertX that allows authenticated users to read arbitrary server files due to the lack of the --sandbox flag in the Pandoc converter. Defenders should prioritize verifying the presence of this vulnerability in their installations, especially if using version 0.19.0 or earlier, and implement compensating controls to mitigate unauthorized file access risks.
- Potential unauthorized access to sensitive server files
- Possible data breaches due to file contents exposure
- Need for verification of ConvertX version and patch application
- Requirement for enhanced monitoring of file access patterns
Technical summary
The vulnerability in ConvertX through version 0.19.0 allows authenticated users to read arbitrary server files. This is possible because the Pandoc converter is invoked without the --sandbox flag. An attacker can exploit this by uploading a reStructuredText document with an include directive that names an absolute path on the server. When the document is converted, the output will contain the contents of the referenced file, allowing unauthorized access to server files.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their ConvertX installations, especially if the version is 0.19.0 or earlier, and ensure that appropriate compensating controls are in place to mitigate the risk of unauthorized file access.
Recommended defensive actions
- Verify ConvertX version and apply patches if available
- Restrict access to sensitive server files
- Monitor for suspicious file access attempts
- Implement additional security measures for file access control
- Perform vulnerability scanning to identify exposed systems
- Review system logs for indicators of compromise
- Conduct a thorough risk assessment to prioritize mitigation efforts
Evidence notes
The CVE record and source item provide details about the vulnerability, including its existence in ConvertX versions up to 0.19.0 and the mechanism of exploitation through the Pandoc converter. However, specific details about affected environments, exploitation attempts, or successful attacks are not provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108694 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108694
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108694 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108694
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
ConvertX through 0.19.0 Arbitrary File Read via Pandoc Converter
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108694.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/C4illin/ConvertX/issues/668
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/C4illin/ConvertX
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://github.com/C4illin/ConvertX/blob/710bc7c71712af04198a39f003e3ea1aa5168a31/src/converters/pandoc.ts
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/convertx-through-0.19.0-arbitrary-file-read-via-pandoc-converter
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.