CVE-2026-25636

Description

A flaw was found in Calibre, an e-book manager. This path traversal vulnerability allows a malicious EPUB (electronic publication) file to corrupt arbitrary files on the system that the Calibre process has write access to. During EPUB conversion, Calibre incorrectly resolves file paths, enabling an attacker to write to locations outside the intended conversion directory. This can lead to significant data integrity issues and potential denial of service.

Statement

This IMPORTANT vulnerability in Calibre allows a malicious EPUB file to corrupt arbitrary files and potentially execute code due to a path traversal flaw during EPUB conversion. This affects Calibre versions 9.1.0 and earlier, including those shipped in Red Hat Community Projects like Fedora 42 and 43. Exploitation requires processing a specially crafted EPUB file.

Mitigation

To mitigate this issue, users should avoid processing untrusted EPUB files with Calibre. If Calibre is not required, consider removing the package to eliminate the attack surface.

Frequently Asked Questions

Want to get errata notifications? Sign up here.