CVE Explorer
CVE-2026-24741
ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the `POST /delete` endpoint uses a user-controlled `filename` value to construct a filesystem path and deletes it via `unlink` without sufficient validation. By supplying path traversal sequences (e.g., `../`), an attacker can delete arbitrary files outside the intended uploads directory, limited only by the permissions of the server process. Version 0.17.0 fixes the issue.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"ConvertX","vendor":"C4illin","versions":[{"status":"affected","version":"< 0.17.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:56dc0bee7ea0be26f7ff43e7502fa5a1117df88676e5b162cb1d29e73e63edba · sha256:f01abc9f38ba1dc4… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:56dc0bee7ea0be26f7ff43e7502fa5a1117df88676e5b162cb1d29e73e63edba · sha256:f01abc9f38ba1dc4… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:56dc0bee7ea0be26f7ff43e7502fa5a1117df88676e5b162cb1d29e73e63edba · sha256:f01abc9f38ba1dc4… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/C4illin/ConvertX/commit/7a936bdc0463936463616381ca257b13babc5e77","tags":["x_refsource_MISC"],"url":"https://github.com/C4illin/ConvertX/commit/7a936bdc0463936463616381ca257b13babc5e77"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:56dc0bee7ea0be26f7ff43e7502fa5a1117df88676e5b162cb1d29e73e63edba · sha256:f01abc9f38ba1dc4… · /containers/cna/references/1
{"name":"https://github.com/C4illin/ConvertX/security/advisories/GHSA-w372-w6cr-45jp","tags":["x_refsource_CONFIRM"],"url":"https://github.com/C4illin/ConvertX/security/advisories/GHSA-w372-w6cr-45jp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:56dc0bee7ea0be26f7ff43e7502fa5a1117df88676e5b162cb1d29e73e63edba · sha256:f01abc9f38ba1dc4… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.