Description
calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. This vulnerability is fixed in 9.2.0.
Published: 2026-02-06
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Calibre, an e‑book manager, contains a path traversal flaw in its CHM reader that permits arbitrary file writes when a user opens a malicious CHM file. The weakness allows an attacker to place files, such as a malicious executable, in any location where the user has write permission. On Windows, an attacker can write a payload into the Startup folder, causing the payload to be executed the next time the user logs in. This vulnerability results in full code execution on the victim’s machine and disrupts system security and integrity. The weakness is classified as CWE‑22.

Affected Systems

The vulnerable product is Calibre developed by Kovid Goyal. The issue is present in all releases prior to version 9.2.0. Users running any of those versions on operating systems that allow write access to arbitrary directories are at risk. The software appears in the Calibre‑ebook vendor entry in the Common Platform Enumeration database.

Risk and Exploitability

Based on the description, the likely attack vector is the local or remote delivery of a crafted CHM file, such as through phishing or compromised content stores. Once the file is parsed by Calibre, the attacker can write to locations under the user’s privilege. On Windows this enables remote code execution by persisting a payload in the Startup folder. The CVSS score of 8.6 signals a high severity of this flaw, while the EPSS score of less than 1 % indicates a low probability that the vulnerability will be actively exploited in the near term. The vulnerability has not yet appeared in the CISA KEV catalogue, so there are no publicly reported active exploits, but the high CVSS warrants proactive mitigation.

Generated by OpenCVE AI on April 18, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Calibre to version 9.2.0 or later to eliminate the path traversal flaw.
  • Avoid opening CHM files from untrusted or unknown sources; treat all CHM content as potentially malicious.
  • Restrict the user account that runs Calibre so it cannot write to system startup directories—or disable automatic execution of programs placed in the Startup folder.

Generated by OpenCVE AI on April 18, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 17 Feb 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Calibre-ebook
Calibre-ebook calibre
CPEs cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*
Vendors & Products Calibre-ebook
Calibre-ebook calibre

Wed, 11 Feb 2026 15:30:00 +0000

Type Values Removed Values Added
References

Tue, 10 Feb 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 09 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Kovidgoyal
Kovidgoyal calibre
Vendors & Products Kovidgoyal
Kovidgoyal calibre

Fri, 06 Feb 2026 20:30:00 +0000

Type Values Removed Values Added
Description calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. This vulnerability is fixed in 9.2.0.
Title calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Calibre-ebook Calibre
Kovidgoyal Calibre
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-11T14:54:23.143Z

Reserved: 2026-02-04T05:15:41.790Z

Link: CVE-2026-25635

cve-icon Vulnrichment

Updated: 2026-02-11T14:54:23.143Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-06T21:16:18.690

Modified: 2026-02-17T21:27:17.940

Link: CVE-2026-25635

cve-icon Redhat

Severity : Important

Publid Date: 2026-02-06T20:10:29Z

Links: CVE-2026-25635 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T13:30:45Z

Weaknesses