Skip to finding
important · Edge / RCE

A normal ConvertX account can execute code by uploading a Calibre recipe.

Affects

ConvertX, a self-hosted online file-conversion service normally deployed as a Linux container.

ConvertX passed uploaded recipe files to ebook-convert, which treats them as executable Python.

Detail and 4 sources

Authentication is required by default, while ALLOW_UNAUTHENTICATED deployments expose a cheaper route.

The upstream fix rejects both executable recipe extensions before invoking ebook-convert.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, October 4, 2026