Path traversal in Calibre - #VU146753
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to overwrite arbitrary files on the server filesystem.
The vulnerability exists due to path traversal in the Content Server /conversion/start endpoint when processing a crafted output_fmt parameter. A remote user can send a specially crafted conversion request to overwrite arbitrary files on the server filesystem.
Trusted IP access may also be sufficient without authentication in some configurations, and the target library must contain at least one book with a convertible format.