CVE 9.3 CRITICAL

calibre is vulnerable to arbitrary code execution when opening FB2 files_CVE-2025-64486

9.3 / 10
CRITICAL
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesystem when viewing or converting a malicious FictionBook file. This can be leveraged to achieve arbitrary code execution. This issue is fixed in version 8.14.0.

AI Analysis

Arbitrary code execution vulnerability in calibre when opening FB2 files

Basic Information

ID CVE-2025-64486
Source GitHub_M
Published Nov 7, 2025 at 23:25

Affected Product

Vendor kovidgoyal
Product calibre
Version < 8.14.0
Affected Versions kovidgoyal calibre < 8.14.0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor kovidgoyal
Product calibre
Version < 8.14.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.