Calibre · Calibre · CVE-2024-6781
**Name of the Vulnerable Software and Affected Versions**
Calibre versions prior to 7.14.0
**Description**
The issue is related to path traversal in the software, allowing unauthenticated attackers to achieve arbitrary file read. This is due to incorrect restriction of the directory path name with limited access. Exploitation of the issue may allow a remote attacker to disclose protected information.
**Recommendations**
For Calibre versions prior to 7.14.0, update to version 7.14.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.