PT-2025-51348 · Convertx · Convertx

Published

2025-12-16

·

Updated

2025-12-21

·

CVE-2025-66449

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ConvertX versions prior to 0.16.0
Description ConvertX is a self-hosted online file converter. The /upload endpoint allows an authenticated user to write arbitrary files on the system, potentially overwriting binaries and enabling code execution. The file.name parameter, received from user input, lacks proper sanitization, allowing for arbitrary file write. This could allow an attacker to overwrite system binaries with malicious files, leading to full code execution.
Recommendations Update to version 0.16.0.

Exploit

Fix

Unrestricted File Upload

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-66449
GHSA-CPWW-GWGC-P72R

Affected Products

Convertx