PT-2026-56263 · Unknown · Koodo-Reader

·

CVE-2026-55408

·

Published

2026-07-07

·

Updated

2026-07-07

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Koodo Reader versions prior to 2.3.1
Description Remote code execution is possible through the import and opening of malicious EPUB files. The issue occurs because the open-book IPC handler enables nodeIntegrationInSubFrames and EPUB chapter content is rendered using unsanitized innerHTML. This allows an attacker to instantiate a hidden iframe with Node.js API access to execute arbitrary operating system commands with the privileges of the victim user.
Recommendations Update to version 2.3.1.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55408
GHSA-MJR7-W4JQ-2RQ9

Affected Products

Koodo-Reader