PT-2026-70939 · Calibre · Calibre

CVE-2026-73248

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions calibre versions prior to 9.12.0
Description An issue exists where the software processes attacker-controlled composite template metadata from malicious EPUB, OPF, PDF, or similar files. This occurs through the program: sequence and a nested template() call where the formatter fails to inherit allow python templates=False. This flaw allows a nested python: template to reach the compile python template function, leading to the execution of arbitrary Python code when the affected file is opened or imported.
Recommendations Update to version 9.12.0.

Exploit

Fix

RCE

Eval Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73248
GHSA-4F7G-RJFP-HMVX

Affected Products

Calibre