calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. This vulnerability is fixed in 9.2.0.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. This vulnerability is fixed in 9.2.0. | |
| Title | calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-06T20:10:29.839Z
Reserved: 2026-02-04T05:15:41.790Z
Link: CVE-2026-25635
No data.
Status : Received
Published: 2026-02-06T21:16:18.690
Modified: 2026-02-06T21:16:18.690
Link: CVE-2026-25635
No data.
OpenCVE Enrichment
No data.