PT-2026-6787 · Calibre · Calibre
0X5T
·
Published
2026-02-06
·
Updated
2026-04-21
·
CVE-2026-25635
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
calibre versions prior to 9.2.0
Description
calibre is an e-book manager. The CHM reader contains a path traversal flaw that permits arbitrary file writes in locations where the user possesses write access. On Windows operating systems, this can potentially result in Remote Code Execution by writing a malicious payload to the Startup folder, which is then executed upon the next user login.
Recommendations
Update to calibre version 9.2.0.
Exploit
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Calibre