
CVE-2026-25731 calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code exec… https://www.cve.org/CVERecord?id=CVE-2026-25731
Post summary
The text announces a Server‑Side Template Injection vulnerability in Calibre versions before 9.2.0 that permits arbitrary code execution, but provides no PoC, exploit code, patch, or evidence of active exploitation.

