PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108694 C4illin CVE debrief

CVE-2026-108694 is a high-severity vulnerability in ConvertX, a product by C4illin, which allows authenticated users to read arbitrary server files. The vulnerability exists because the Pandoc converter in ConvertX does not use the --sandbox flag, enabling attackers to exploit this weakness by uploading a specially crafted reStructuredText document with an include directive pointing to an absolute path on the server. This can lead to unauthorized access to sensitive server files.

Vendor
C4illin
Product
ConvertX
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

System administrators and security teams responsible for ConvertX installations, especially those using version 0.19.0 or earlier, should assess their exposure and take necessary actions to mitigate the risk. This includes verifying the version of ConvertX in use, restricting access to sensitive files, and monitoring for suspicious activities that could indicate exploitation attempts.

Why it matters

CVE-2026-108694 is a high-severity vulnerability in ConvertX that allows authenticated users to read arbitrary server files due to the lack of the --sandbox flag in the Pandoc converter. Defenders should prioritize verifying the presence of this vulnerability in their installations, especially if using version 0.19.0 or earlier, and implement compensating controls to mitigate unauthorized file access risks.

  • Potential unauthorized access to sensitive server files
  • Possible data breaches due to file contents exposure
  • Need for verification of ConvertX version and patch application
  • Requirement for enhanced monitoring of file access patterns

Technical summary

The vulnerability in ConvertX through version 0.19.0 allows authenticated users to read arbitrary server files. This is possible because the Pandoc converter is invoked without the --sandbox flag. An attacker can exploit this by uploading a reStructuredText document with an include directive that names an absolute path on the server. When the document is converted, the output will contain the contents of the referenced file, allowing unauthorized access to server files.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their ConvertX installations, especially if the version is 0.19.0 or earlier, and ensure that appropriate compensating controls are in place to mitigate the risk of unauthorized file access.

Recommended defensive actions

  • Verify ConvertX version and apply patches if available
  • Restrict access to sensitive server files
  • Monitor for suspicious file access attempts
  • Implement additional security measures for file access control
  • Perform vulnerability scanning to identify exposed systems
  • Review system logs for indicators of compromise
  • Conduct a thorough risk assessment to prioritize mitigation efforts

Evidence notes

The CVE record and source item provide details about the vulnerability, including its existence in ConvertX versions up to 0.19.0 and the mechanism of exploitation through the Pandoc converter. However, specific details about affected environments, exploitation attempts, or successful attacks are not provided in the source corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108694 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108694

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108694 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108694

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • ConvertX through 0.19.0 Arbitrary File Read via Pandoc Converter

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108694.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/C4illin/ConvertX/issues/668

    Supplemental source - issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/C4illin/ConvertX

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://github.com/C4illin/ConvertX/blob/710bc7c71712af04198a39f003e3ea1aa5168a31/src/converters/pandoc.ts

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/convertx-through-0.19.0-arbitrary-file-read-via-pandoc-converter

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.