Vulnerability Description
Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files because the open-book IPC handler enables nodeIntegrationInSubFrames and EPUB chapter content is rendered with unsanitized innerHTML. An attacker can craft an EPUB book that, when imported and opened by the victim, instantiates a hidden iframe with Node.js API access and executes arbitrary operating system commands with the victim user's privileges. This issue is fixed in version 2.3.1.
Related Weaknesses (CWE)
References
- https://github.com/koodo-reader/koodo-reader/security/advisories/GHSA-mjr7-w4jq-
- https://github.com/koodo-reader/koodo-reader/security/advisories/GHSA-mjr7-w4jq-
FAQ
What is CVE-2026-55408?
CVE-2026-55408 is a documented vulnerability. Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files because the open-book IPC handler enables nodeIntegratio...
How severe is CVE-2026-55408?
CVSS scoring is not yet available for CVE-2026-55408. Check NVD for updates.
Is there a patch for CVE-2026-55408?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.