CVE-2026-25636 - calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execu...

CVE-2026-25636 - calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execu...

CVE ID : CVE-2026-25636 Published : Feb. 6, 2026, 8:07 p.m. | 37 minutes ago Description : calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre resolves CipherReference URI from META-INF/encryption.xml to an absolute filesystem path and opens it in read-write mode, even when it points outside the conversion extraction directory. This vulnerability is fixed in 9.2.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
Feb. 6, 2026
Impact: path traversal