CVE-2026-25636: calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execution
calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre resolves CipherReference URI from META-INF/encryption.xml to an absolute filesystem path and opens it in read-write mode, even when it points outside the conversion extraction directory. This vulnerability is fixed in 9.2.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25636?
CVE-2026-25636 is a high severity vulnerability due to its potential for arbitrary file corruption and code execution.
How do I fix CVE-2026-25636?
To fix CVE-2026-25636, upgrade Calibre to version 9.2.0 or later.
What are the potential impacts of CVE-2026-25636?
The potential impacts of CVE-2026-25636 include arbitrary file corruption and unauthorized code execution on systems running affected versions of Calibre.
Which versions of Calibre are affected by CVE-2026-25636?
CVE-2026-25636 affects Calibre versions 9.1.0 and earlier.
What type of vulnerability is CVE-2026-25636?
CVE-2026-25636 is classified as a path traversal vulnerability.