Unknown · Koodo-Reader · CVE-2026-55408
**Name of the Vulnerable Software and Affected Versions**
Koodo Reader versions prior to 2.3.1
**Description**
Remote code execution is possible through the import and opening of malicious EPUB files. The issue occurs because the open-book IPC handler enables `nodeIntegrationInSubFrames` and EPUB chapter content is rendered using unsanitized `innerHTML`. This allows an attacker to instantiate a hidden iframe with Node.js API access to execute arbitrary operating system commands with the privileges of the victim user.
**Recommendations**
Update to version 2.3.1.