CVE-2026-25635
EUVD-2026-559606.02.2026, 21:16
calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. This vulnerability is fixed in 9.2.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| calibre-ebook | calibre | 𝑥 < 9.2.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases