PatchSiren

C4illin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH C4illin CVE published 2026-10-11

CVE-2026-108694

CVE-2026-108694 is a high-severity vulnerability in ConvertX, a product by C4illin, which allows authenticated users to read arbitrary server files. The vulnerability exists because the Pandoc converter in ConvertX does not use the --sandbox flag, enabling attackers to exploit this weakness by uploading a specially crafted reStructuredText document with an include directive pointing to an absolute path on [truncated]