Unrated severityNVD Advisory· Published Jul 7, 2026· Updated Jul 8, 2026
Koodo Reader: Remote code execution via malicious epub file
CVE-2026-55408
Description
Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files because the open-book IPC handler enables nodeIntegrationInSubFrames and EPUB chapter content is rendered with unsanitized innerHTML. An attacker can craft an EPUB book that, when imported and opened by the victim, instantiates a hidden iframe with Node.js API access and executes arbitrary operating system commands with the victim user's privileges. This issue is fixed in version 2.3.1.
Affected products
1- Range: <=2.3.0
Patches
Vulnerability mechanics
References
1- github.com/koodo-reader/koodo-reader/security/advisories/GHSA-mjr7-w4jq-2rq9mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.