Unrated severityNVD Advisory· Published Feb 6, 2026· Updated Feb 6, 2026
Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML Export
CVE-2026-25731
Description
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This vulnerability is fixed in 9.2.0.
Affected products
2- Range: <9.2.0
- kovidgoyal/calibrev5Range: < 9.2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/kovidgoyal/calibre/commit/f0649b27512e987b95fcab2e1e0a3bcdafc23379mitrex_refsource_MISC
- github.com/kovidgoyal/calibre/security/advisories/GHSA-xrh9-w7qx-3gccmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.