8.6
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Description
calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. This vulnerability is fixed in 9.2.0.
AI Analysis
Path Traversal Leading to Arbitrary File Write and Potential Code Execution
Basic Information
ID
CVE-2026-25635
Source
GitHub_M
Published
Feb 6, 2026 at 20:10
Affected Product
Vendor
kovidgoyal
Product
calibre
Version
< 9.2.0
Affected Versions
kovidgoyal calibre < 9.2.0
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
kovidgoyal
Product
calibre
Version
< 9.2.0