VYPR

Convertx

by C4illin

Source repositories

CVEs (3)

  • CVE-2026-85618MedSep 4, 2026
    risk 0.35cvss 6.5epss 0.00

    ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input directives. Attackers can upload .tex files containing \\input{path} or \\verbatiminput{path} directives to…

  • CVE-2026-24741HigJan 27, 2026
    risk 0.00cvss 8.1epss 0.00

    ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the `POST /delete` endpoint uses a user-controlled `filename` value to construct a filesystem path and deletes it via `unlink` without sufficient validation. By supplying path traversal sequences (e.g.,…

  • CVE-2025-66449HigDec 16, 2025
    risk 0.00cvss 8.8epss 0.01

    ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwriting binaries and allowing code execution. The upload function takes `file.name` directly from user…