Arbitrary Code Execution Vulnerability in Calibre e-Book Manager
CVE-2026-73248

8.5HIGH

Key Information:

Vendor

Kovidgoyal

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73248?

The Calibre e-book manager, used for managing and converting e-book formats, contains a security flaw that allows attackers to execute arbitrary Python code. This vulnerability arises from improper processing of attacker-controlled composite_template metadata within malicious EPUB, OPF, or PDF files. When such files are opened or imported, it leverages a nested python: template that bypasses safeguards, posing significant risks to users. This critical issue has been addressed in version 9.12.0.

Affected Version(s)

calibre < 9.12.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.