Improper Neutralization of Special Elements Used in a Template Engine in Calibre - CVE-2026-25731
Published: June 29, 2026
Calibre
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to server-side template injection in the HTML export feature when processing crafted template content during conversion. A remote attacker can embed template expressions in a crafted input to execute arbitrary code.
User interaction is required to open or convert crafted content.