Description
link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3862-1 | calibre security update |
EUVD |
EUVD-2023-50525 | link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root. |
References
History
Tue, 04 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-04T16:10:39.079Z
Reserved: 2023-10-22T00:00:00.000Z
Link: CVE-2023-46303
Updated: 2025-11-04T16:10:39.079Z
Status : Modified
Published: 2023-10-22T18:15:08.577
Modified: 2025-11-04T17:15:38.210
Link: CVE-2023-46303
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD