Executive brief
ConvertX is a self-hosted file conversion service that supports converting LaTeX documents to PDF. An authenticated attacker can upload specially crafted LaTeX files containing input directives (like \input{/etc/passwd}) to force the server to read arbitrary files and include their contents in the generated PDF, exposing sensitive system files or application data.
Technical details
The vulnerability is an arbitrary file read in the xelatex converter component caused by insufficient input sanitization of LaTeX directives. When a user uploads a .tex file, the converter passes it directly to the latexmk/xelatex command without filtering dangerous TeX macros like \input{} and \verbatiminput{} that can reference arbitrary filesystem paths. An authenticated attacker can exploit this by uploading a malicious .tex file containing these directives; the TeX engine then reads the specified files and includes their content in the output PDF. The attack requires authentication and file upload capability. A fix is available in version 0.18.0 or later.
Affected products
- C4illin ConvertX 0.17.0
Timeline
- 2026-09-04: disclosed