CVE-2026-25636 Details
Description
calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre resolves CipherReference URI from META-INF/encryption.xml to an absolute filesystem path and opens it in read-write mode, even when it points outside the conversion extraction directory. This vulnerability is fixed in 9.2.0.
A path traversal vulnerability has been identified in Calibre's EPUB conversion process, allowing a malicious EPUB file to corrupt arbitrary existing files that are writable by the Calibre process. This issue affects Calibre versions through 9.1.0. During the conversion, Calibre improperly resolves CipherReference URIs from the encryption metadata of EPUB files to absolute filesystem paths. It opens these paths in read-write mode, even when they point outside the designated conversion directory. As a result, files outside the EPUB extraction directory can be modified, leading to corruption. This vulnerability has been confirmed on Calibre 9.1.0, both on Windows 11 (x64) and Linux.
Users can update to Calibre version 9.2.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://0x5t.raptx.org/posts/calibre-epub-rce | CVE | ExploitThird Party Advisory |
| https://github.com/kovidgoyal/calibre/commit/9484ea82c6ab226c18e6ca5aa000fa16de598726 | [email protected] | Patch |
| https://github.com/kovidgoyal/calibre/security/advisories/GHSA-8r26-m7j5-hm29 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-73 | External Control of File Name or Path | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| calibre-ebook calibre | < 9.2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 17, 2026 | Initial Analysis | [email protected] |
| Feb 11, 2026 | CVE Modified | CVE |
| Feb 6, 2026 | New CVE Received | [email protected] |