CVE-2026-53511: calibre: Arbitrary Code Execution in Template Formatter via Book Metadata
calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read by calibre, including through Add books or Edit books, by embedding a custom column definition with a python: template in calibre:usermetadata that is passed unsanitized to exec() in the template formatter. This issue is fixed in version 9.10.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
calibreto a version that resolves this vulnerability.Fixed in 9.10.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53511?
CVE-2026-53511 has a severity rating of high with a CVSS score of 8.5.
How do I fix CVE-2026-53511?
To fix CVE-2026-53511, upgrade calibre to version 9.10.0 or later.
What types of files are affected by CVE-2026-53511?
CVE-2026-53511 affects EPUB, OPF, and PDF files that contain malicious metadata.
What kind of attack is possible with CVE-2026-53511?
CVE-2026-53511 allows an attacker to execute arbitrary Python code through crafted book metadata.
In which version of calibre was the vulnerability CVE-2026-53511 fixed?
The vulnerability CVE-2026-53511 was fixed in calibre version 9.10.0.