216.73.216.133

CVE-2026-33206

· Published 27/03/2026 15:16 · Modified 27/03/2026 15:16

Labels: CVE-2026-33206 2026-03-27CVE-2026-33206CWE-23[email protected]

Essential information

Published
27/03/2026 15:16
Modified
27/03/2026 15:16
Author
Creator
CVSS
8.2 HIGH (v3) 8.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar text-based files allowing an attacker to include arbitrary files from the file system into the converted book. Additionally, missing authentication and server-side request forgery in the background-image endpoint in the ebook reader web view allow the files to be exfiltrated without additional interaction. Version 9.6.0 contains a fix.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
calibre / calibre cpe:2.3:a:calibre:calibre:*:*:*:*:*:*:*:*
calibre / calibre cpe:2.3:a:calibre:calibre:9.6.0:*:*:*:*:*:*:*

References