PT-2026-28474 · Calibre · Calibre

Emilvirkki

·

Published

2026-03-27

·

Updated

2026-04-21

·

CVE-2026-33206

CVSS v4.0

8.2

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions calibre versions prior to 9.6.0
Description A path traversal issue exists in the handling of images within Markdown and similar text-based files, which allows an attacker to include arbitrary files from the file system into a converted book. Furthermore, the 'background-image' endpoint in the ebook reader web view lacks authentication and is susceptible to server-side request forgery (SSRF), a flaw where the server is tricked into making unintended requests, enabling the exfiltration of files without further interaction.
Recommendations Update to version 9.6.0.

Exploit

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2026-33206
GHSA-H3P4-M74F-43G6
OPENSUSE-SU-2026:10587-1

Affected Products

Calibre