High severity8.6NVD Advisory· Published Feb 6, 2026· Updated Jun 17, 2026
CVE-2026-25635
CVE-2026-25635
Description
calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. This vulnerability is fixed in 9.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4< 9.2.0+ 1 more
- (no CPE)range: < 9.2.0
- cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*range: <9.2.0
Patches
Vulnerability mechanics
References
3- github.com/kovidgoyal/calibre/commit/9739232fcb029ac15dfe52ccd4fdb4a07ebb6ce9nvdPatch
- 0x5t.raptx.org/posts/calibre-chm-rcenvdExploitThird Party Advisory
- github.com/kovidgoyal/calibre/security/advisories/GHSA-32vh-whvh-9fxrnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.