Unrated severityNVD Advisory· Published Feb 6, 2026· Updated Feb 6, 2026
Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML Export
CVE-2026-25731
Description
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This vulnerability is fixed in 9.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<9.2.0+ 1 more
- (no CPE)range: <9.2.0
- (no CPE)range: < 9.2.0
Patches
Vulnerability mechanics
References
2- github.com/kovidgoyal/calibre/commit/f0649b27512e987b95fcab2e1e0a3bcdafc23379mitrex_refsource_MISC
- github.com/kovidgoyal/calibre/security/advisories/GHSA-xrh9-w7qx-3gccmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.