PT-2026-6787 · Calibre · Calibre

0X5T

·

Publicado

2026-02-06

·

Atualizado

2026-04-21

·

CVE-2026-25635

CVSS v3.1

8.6

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions calibre versions prior to 9.2.0
Description calibre is an e-book manager. The CHM reader contains a path traversal flaw that permits arbitrary file writes in locations where the user possesses write access. On Windows operating systems, this can potentially result in Remote Code Execution by writing a malicious payload to the Startup folder, which is then executed upon the next user login.
Recommendations Update to calibre version 9.2.0.

Exploit

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25635
GHSA-32VH-WHVH-9FXR
OPENSUSE-SU-2026:10587-1

Produtos afetados

Calibre