CVE-2026-24741: ConvertX Vulnerable to Arbitrary File Deletion via Path Traversal in `POST /delete`
ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the POST /delete endpoint uses a user-controlled filename value to construct a filesystem path and deletes it via unlink without sufficient validation. By supplying path traversal sequences (e.g., ../), an attacker can delete arbitrary files outside the intended uploads directory, limited only by the permissions of the server process. Version 0.17.0 fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24741?
CVE-2026-24741 has a medium severity due to its potential for arbitrary file deletion.
How do I fix CVE-2026-24741?
To fix CVE-2026-24741, upgrade to ConvertX version 0.17.0 or later.
What versions are affected by CVE-2026-24741?
CVE-2026-24741 affects all versions of ConvertX prior to 0.17.0.
What is the cause of CVE-2026-24741?
CVE-2026-24741 is caused by a path traversal vulnerability in the `POST /delete` endpoint.
Who is impacted by CVE-2026-24741?
Users running ConvertX versions earlier than 0.17.0 are impacted by CVE-2026-24741.