External Control of File Name or Path in Calibre - #VU146751
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to write arbitrary files.
The vulnerability exists due to improper neutralization of special elements in the fb2 import XSLT stylesheet when parsing a crafted .fb2 book. A remote attacker can supply a malicious book with an injected namespace to write arbitrary files.
The payload runs automatically during page counting after the book is added, and no manual conversion or special configuration is required.