CVE-2026-73248: calibre: Bypass of Python template restrictions via nested `template()` leading to RCE
calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled compositetemplate metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inherit allowpythontemplates=False, allowing a nested python: template to reach compilepythontemplate and execute arbitrary Python code when the file is opened or imported. This issue is fixed in version 9.12.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
calibreto a version that resolves this vulnerability.Fixed in 9.12.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73248?
CVE-2026-73248 has a severity score of 80, indicating a high-risk vulnerability.
How do I fix CVE-2026-73248?
To fix CVE-2026-73248, upgrade to Calibre version 9.12.0 or later.
What type of vulnerability is CVE-2026-73248?
CVE-2026-73248 is classified as a Code Injection vulnerability.
What can an attacker do with CVE-2026-73248?
An attacker can exploit CVE-2026-73248 to execute remote code through the processing of malicious metadata in e-books.
Which versions of Calibre are affected by CVE-2026-73248?
CVE-2026-73248 affects all versions of Calibre prior to 9.12.0.