Code Injection in Calibre - #VU146754
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper control of code generation in the Content Server upload endpoints and recipe conversion pipeline when uploading a crafted downloaded_recipe file and triggering conversion. A remote user can upload a malicious .downloaded_recipe archive and start a conversion job to execute arbitrary code.
Write access to the Content Server is required, and code runs with the privileges of the calibre server process.