CVE-2026-55408EPSS p14.4%
CVE-2026-55408CVE-2026-55408
Description
Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files because the open-book IPC handler enables nodeIntegrationInSubFrames and EPUB chapter content is rendered with unsanitized innerHTML. An attacker can craft an EPUB book that, when imported and opened by the victim, instantiates a hidden iframe with Node.js API access and executes arbitrary operating system commands with the victim user's privileges. This issue is fixed in version 2.3.1.
Scoring
| EPSS | 0.25% probability of exploitation · percentile 14.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-08 |