CVE-2026-25635
Description
A flaw was found in Calibre's CHM reader. This path traversal vulnerability allows an attacker to write arbitrary files to locations where the user has write permissions. On Windows systems, this could lead to remote code execution by placing a malicious file in the Startup folder, which would then execute upon the user's next login. This vulnerability primarily results in arbitrary code execution.
Statement
This IMPORTANT flaw in Calibre's CHM reader allows an attacker to perform path traversal, leading to arbitrary file writes. This could enable an attacker to write malicious files to arbitrary locations on the filesystem where the user has write permissions. Exploitation requires a user to open a specially crafted CHM file.
Mitigation
Users should avoid opening untrusted CHM files with Calibre. This operational control reduces the risk of exploitation by preventing the processing of malicious content.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.