CVE-2026-25731: Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML Export
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This vulnerability is fixed in 9.2.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25731?
CVE-2026-25731 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2026-25731?
To fix CVE-2026-25731, upgrade Calibre to version 9.2.0 or later.
What causes CVE-2026-25731 in Calibre?
CVE-2026-25731 is caused by a Server-Side Template Injection vulnerability in Calibre's Templite templating engine.
What versions of Calibre are affected by CVE-2026-25731?
CVE-2026-25731 affects all versions of Calibre prior to 9.2.0.
Can CVE-2026-25731 be exploited remotely?
Yes, CVE-2026-25731 can be exploited remotely if an attacker can trigger the vulnerable templating feature.