CVE-2026-25731
Description
A flaw was found in Calibre, an e-book manager. This Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows an attacker to achieve arbitrary code execution. This occurs when a user converts an ebook using a specially crafted malicious custom template file, provided via the --template-html or --template-html-index command-line options. This could lead to a complete compromise of the affected system.
Statement
This is an IMPORTANT arbitrary code execution vulnerability in Calibre's HTML export functionality. It occurs when a user processes an ebook with a specially crafted custom template file using the --template-html or --template-html-index command-line options. This issue affects Calibre versions prior to 9.2.0, as distributed in Fedora 42 and Fedora 43.
Mitigation
To mitigate this vulnerability, users should avoid converting ebooks using untrusted or malicious custom template files with the `--template-html` or `--template-html-index` command-line options. Only use template files from trusted sources.
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Application Data
Integrity
Technical Impact: Execute Unauthorized Code or Commands
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.