External Control of File Name or Path in Calibre - #VU146751

 

External Control of File Name or Path in Calibre - #VU146751

Published: September 2, 2026


Vulnerability identifier: #VU146751
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-73
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write arbitrary files.

The vulnerability exists due to improper neutralization of special elements in the fb2 import XSLT stylesheet when parsing a crafted .fb2 book. A remote attacker can supply a malicious book with an injected namespace to write arbitrary files.

The payload runs automatically during page counting after the book is added, and no manual conversion or special configuration is required.


Affected software

Calibre

Remediation

Install security update from vendor's website.

Calibre - update to 9.14.0

External References

Related Security Bulletins