Path traversal in Calibre - #VU146753

 

Path traversal in Calibre - #VU146753

Published: September 2, 2026


Vulnerability identifier: #VU146753
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to overwrite arbitrary files on the server filesystem.

The vulnerability exists due to path traversal in the Content Server /conversion/start endpoint when processing a crafted output_fmt parameter. A remote user can send a specially crafted conversion request to overwrite arbitrary files on the server filesystem.

Trusted IP access may also be sufficient without authentication in some configurations, and the target library must contain at least one book with a convertible format.


Affected software

Calibre

Remediation

Install security update from vendor's website.

Calibre - update to 9.14.0

External References

Related Security Bulletins