Cross-site scripting in Calibre - #VU146756

 

Cross-site scripting in Calibre - #VU146756

Published: September 2, 2026


Vulnerability identifier: #VU146756
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's browser.

The vulnerability exists due to cross-site scripting in the legacy content server book details page when rendering crafted identifier metadata through the /legacy/book/{book_id}/{library_id} endpoint. A remote user can upload or add a malicious EPUB with a crafted dc:identifier value to execute arbitrary JavaScript in the victim's browser.

User interaction is required to view the affected legacy book details page, and the legacy endpoint remains reachable through older clients and direct URLs.


Affected software

Calibre

Remediation

Install security update from vendor's website.

Calibre - update to 9.14.0

External References

Related Security Bulletins