Input validation error in Calibre - CVE-2025-64486
Published: November 28, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to the application does not validate filenames when handling binary assets in FB2 files. A remote attacker can trick the victim into converting a malicious FictionBook file and write files to arbitrary locations on the system, leading to system compromise.
Affected software
Fedora
calibre
How to mitigate CVE-2025-64486
calibre - update to 8.14.0-1.fc43