CVE-2026-25731
EUVD-2026-557306.02.2026, 21:16
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This vulnerability is fixed in 9.2.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| calibre-ebook | calibre | 𝑥 < 9.2.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases