Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-25635

Опубликовано: 06 фев. 2026
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. This vulnerability is fixed in 9.2.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*
Версия до 9.2.0 (исключая)

EPSS

Процентиль: 24%
0.00082
Низкий

8.6 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 2 месяцев назад

calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. This vulnerability is fixed in 9.2.0.

CVSS3: 8.6
redhat
около 2 месяцев назад

calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows (haven't tested on other OS's), this can lead to Remote Code Execution by writing a payload to the Startup folder, which executes on next login. This vulnerability is fixed in 9.2.0.

CVSS3: 8.6
debian
около 2 месяцев назад

calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader con ...

EPSS

Процентиль: 24%
0.00082
Низкий

8.6 High

CVSS3

Дефекты

CWE-22