CVE-2026-25636: Calibre-Ebook Calibre
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre resolves CipherReference URI from META-INF/encryption.xml to an absolute filesystem path and opens it in read-write mode, even when it points outside the conversion extraction directory. This vulnerability is fixed in 9.2.0.
Affected products
- Calibre-Ebook Calibre: before 9.2.0 (fixed in 9.2.0)
Published 2026-02-06. Last modified 2026-06-17.