CVE-2026-25635

Description

A flaw was found in Calibre's CHM reader. This path traversal vulnerability allows an attacker to write arbitrary files to locations where the user has write permissions. On Windows systems, this could lead to remote code execution by placing a malicious file in the Startup folder, which would then execute upon the user's next login. This vulnerability primarily results in arbitrary code execution.

Statement

This IMPORTANT flaw in Calibre's CHM reader allows an attacker to perform path traversal, leading to arbitrary file writes. This could enable an attacker to write malicious files to arbitrary locations on the filesystem where the user has write permissions. Exploitation requires a user to open a specially crafted CHM file.

Mitigation

Users should avoid opening untrusted CHM files with Calibre. This operational control reduces the risk of exploitation by preventing the processing of malicious content.

Frequently Asked Questions

Want to get errata notifications? Sign up here.