PT-2026-6787 · Calibre · Calibre

0X5T

·

Published

2026-02-06

·

Updated

2026-04-21

·

CVE-2026-25635

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions calibre versions prior to 9.2.0
Description calibre is an e-book manager. The CHM reader contains a path traversal flaw that permits arbitrary file writes in locations where the user possesses write access. On Windows operating systems, this can potentially result in Remote Code Execution by writing a malicious payload to the Startup folder, which is then executed upon the next user login.
Recommendations Update to calibre version 9.2.0.

Exploit

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-25635
GHSA-32VH-WHVH-9FXR
OPENSUSE-SU-2026:10587-1

Affected Products

Calibre