CVE-2026-25636

calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre resolves CipherReference URI from META-INF/encryption.xml to an absolute filesystem path and opens it in read-write mode, even when it points outside the conversion extraction directory. This vulnerability is fixed in 9.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*

History

17 Feb 2026, 21:23

Type Values Removed Values Added
References () https://github.com/kovidgoyal/calibre/commit/9484ea82c6ab226c18e6ca5aa000fa16de598726 - () https://github.com/kovidgoyal/calibre/commit/9484ea82c6ab226c18e6ca5aa000fa16de598726 - Patch
References () https://github.com/kovidgoyal/calibre/security/advisories/GHSA-8r26-m7j5-hm29 - () https://github.com/kovidgoyal/calibre/security/advisories/GHSA-8r26-m7j5-hm29 - Exploit, Third Party Advisory
References () https://0x5t.raptx.org/posts/calibre-epub-rce - () https://0x5t.raptx.org/posts/calibre-epub-rce - Exploit, Third Party Advisory
CPE cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*
Summary
  • (es) calibre es un gestor de libros electrónicos. En 9.1.0 y versiones anteriores, una vulnerabilidad de salto de ruta en la conversión de EPUB de Calibre permite que un archivo EPUB malicioso corrompa archivos existentes arbitrarios escribibles por el proceso de Calibre. Durante la conversión, Calibre resuelve la URI de CipherReference de META-INF/encryption.xml a una ruta de sistema de archivos absoluta y lo abre en modo de lectura-escritura, incluso cuando apunta fuera del directorio de extracción de la conversión. Esta vulnerabilidad está corregida en 9.2.0.
First Time Calibre-ebook calibre
Calibre-ebook

11 Feb 2026, 15:16

Type Values Removed Values Added
References
  • () https://0x5t.raptx.org/posts/calibre-epub-rce -

06 Feb 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 21:16

Updated : 2026-02-17 21:23


NVD link : CVE-2026-25636

Mitre link : CVE-2026-25636

CVE.ORG link : CVE-2026-25636


JSON object : View

Products Affected

calibre-ebook

  • calibre
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path

CWE-94

Improper Control of Generation of Code ('Code Injection')