CVE-2026-25636

Description

A flaw was found in Calibre, an e-book manager. This path traversal vulnerability allows a malicious EPUB (electronic publication) file to corrupt arbitrary files on the system that the Calibre process has write access to. During EPUB conversion, Calibre incorrectly resolves file paths, enabling an attacker to write to locations outside the intended conversion directory. This can lead to significant data integrity issues and potential denial of service.

Statement

This IMPORTANT vulnerability in Calibre allows a malicious EPUB file to corrupt arbitrary files and potentially execute code due to a path traversal flaw during EPUB conversion. This affects Calibre versions 9.1.0 and earlier, including those shipped in Red Hat Community Projects like Fedora 42 and 43. Exploitation requires processing a specially crafted EPUB file.

Mitigation

To mitigate this issue, users should avoid processing untrusted EPUB files with Calibre. If Calibre is not required, consider removing the package to eliminate the attack surface.

Understanding the Weakness (CWE)

Integrity,Confidentiality,Availability

Technical Impact: Execute Unauthorized Code or Commands

The attacker may be able to create or overwrite critical files that are used to execute code, such as programs or libraries.

Integrity

Technical Impact: Modify Files or Directories

The attacker may be able to overwrite or create critical files, such as programs, libraries, or important data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, appending a new account at the end of a password file may allow an attacker to bypass authentication.

Confidentiality

Technical Impact: Read Files or Directories

The attacker may be able read the contents of unexpected files and expose sensitive data. If the targeted file is used for a security mechanism, then the attacker may be able to bypass that mechanism. For example, by reading a password file, the attacker could conduct brute force password guessing attacks in order to break into an account on the system.

Availability

Technical Impact: DoS: Crash, Exit, or Restart

The attacker may be able to overwrite, delete, or corrupt unexpected critical files such as programs, libraries, or important data. This may prevent the product from working at all and in the case of protection mechanisms such as authentication, it has the potential to lock out product users.

Frequently Asked Questions

Want to get errata notifications? Sign up here.