CVE-2026-25731Patch(calibre-ebook / calibre)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch calibre-ebook calibre systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This vulnerability is fixed in 9.2.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • calibre

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-08)
  • 3 total mentions across 2 days

Affected systems

Products
calibre

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-06: 1Mentions · 2026-02-08: 2Patch / Workaround · 2026-02-08: 2Technical Details · 2026-02-06: 1Technical Details · 2026-02-08: 202-0602-08
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-061
Disclosure1
2026-02-082
Patch2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25731 calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code exec… https://www.cve.org/CVERecord?id=CVE-2026-25731

    Post summary

    The text announces a Server‑Side Template Injection vulnerability in Calibre versions before 9.2.0 that permits arbitrary code execution, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    00010171
    56.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Calibre is affected by an arbitrary code execution vulnerability (CVE-2026-25731) via server-side template injection during HTML export. Upgrade to remediate. #Calibre #AppSec #RCE https://www.pulsepatch.io/posts/cve-2026-25731-calibre-arbitrary-code-execution

    Post summary

    CVE‑2026‑25731 allows arbitrary code execution in Calibre via server‑side template injection during HTML export; users are advised to upgrade to remediate.

    0000065
    1 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Calibre Server-Side Template Injection (SSTI) vulnerability, CVE-2026-25731, allows arbitrary code execution via malicious custom templates. Upgrade to 9.2.0. #Calibre #SSTI #infosec https://www.pulsepatch.io/posts/calibre-ssti-arbitrary-code-execution-cve-2026-25731

    Post summary

    The post announces the CVE‑2026‑25731 SSTI vulnerability that enables arbitrary code execution in Calibre, recommends upgrading to version 9.2.0, and provides a reference link for details.

    0000049
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcalibre-ebookcalibre---

Explore more