PT-2026-53655 · Calibre · Calibre

·

CVE-2026-53511

·

Published

2026-06-27

·

Updated

2026-08-18

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions calibre versions prior to 9.10.0
Description A flaw exists where reading metadata from a malicious EPUB, OPF, or PDF file allows the execution of arbitrary Python code. This occurs when a custom column definition containing a python: template is embedded within calibre:user metadata and subsequently passed unsanitized to the exec() function in the template formatter. This can be triggered through actions such as Add books or Edit books.
Recommendations Update to version 9.10.0.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53511
GHSA-2J4M-2Q7X-2C47
OPENSUSE-SU-2026:11130-1

Affected Products

Calibre