CVE-2026-25731

Description

A flaw was found in Calibre, an e-book manager. This Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows an attacker to achieve arbitrary code execution. This occurs when a user converts an ebook using a specially crafted malicious custom template file, provided via the --template-html or --template-html-index command-line options. This could lead to a complete compromise of the affected system.

Statement

This is an IMPORTANT arbitrary code execution vulnerability in Calibre's HTML export functionality. It occurs when a user processes an ebook with a specially crafted custom template file using the --template-html or --template-html-index command-line options. This issue affects Calibre versions prior to 9.2.0, as distributed in Fedora 42 and Fedora 43.

Mitigation

To mitigate this vulnerability, users should avoid converting ebooks using untrusted or malicious custom template files with the `--template-html` or `--template-html-index` command-line options. Only use template files from trusted sources.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Application Data

Integrity

Technical Impact: Execute Unauthorized Code or Commands

Frequently Asked Questions

Want to get errata notifications? Sign up here.