Code Injection in Calibre - #VU146754

 

Code Injection in Calibre - #VU146754

Published: September 2, 2026


Vulnerability identifier: #VU146754
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper control of code generation in the Content Server upload endpoints and recipe conversion pipeline when uploading a crafted downloaded_recipe file and triggering conversion. A remote user can upload a malicious .downloaded_recipe archive and start a conversion job to execute arbitrary code.

Write access to the Content Server is required, and code runs with the privileges of the calibre server process.


Affected software

Calibre

Remediation

Install security update from vendor's website.

Calibre - update to 9.14.0

External References

Related Security Bulletins