Home

Description

calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This vulnerability is fixed in 9.2.0.

PUBLISHED Reserved 2026-02-05 | Published 2026-02-06 | Updated 2026-02-06 | Assigner GitHub_M




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine

Product status

< 9.2.0
affected

References

github.com/...alibre/security/advisories/GHSA-xrh9-w7qx-3gcc

github.com/...ommit/f0649b27512e987b95fcab2e1e0a3bcdafc23379

cve.org (CVE-2026-25731)

nvd.nist.gov (CVE-2026-25731)

Download JSON