CVE-2026-25635: Calibre-Ebook Calibre
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. This vulnerability is fixed in 9.2.0.
Affected products
- Calibre-Ebook Calibre: before 9.2.0 (fixed in 9.2.0)
Published 2026-02-06. Last modified 2026-06-17.