CVE-2026-25731

Vulnerability

CVE-2026-25731

CVE-2026-25731

 

calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This vulnerability is fixed in 9.2.0.

References
severitym
medium

type: vendor

source: launchpad.net/ubuntu-cve-tracker

published: 2026-02-07 00:00:00

Detection

No detection criteria available for this vulnerability.

Data Sources

  • Ubuntu CVE Tracker

    ubuntu-cve-tracker

VulsFutureVuls|GitHub Logo IconGitHub