Security: kovidgoyal/calibre
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Arbitrary code execution via nested `template()` that bypasses Python template restrictionsGHSA-4f7g-rjfp-hmvx published
Aug 2, 2026 by kovidgoyalHigh -
calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation ModificationGHSA-5x64-w63v-x2g6 published
Aug 2, 2026 by kovidgoyalHigh -
Arbitrary Code Execution in Template Formatter via Book MetadataGHSA-2j4m-2q7x-2c47 published
Jun 26, 2026 by kovidgoyalHigh -
Server-Side Request Forgery in ebook viewer backendGHSA-4926-v9px-wv7v published
Mar 27, 2026 by kovidgoyalModerate -
Path traversal allows reading arbitrary files when converting a text-based fileGHSA-h3p4-m74f-43g6 published
Mar 27, 2026 by kovidgoyalHigh -
Path Traversal Leading to Arbitrary File WriteGHSA-7mp7-rfrg-542x published
Mar 13, 2026 by kovidgoyalModerate -
IP Ban Bypass via X-Forwarded-For Header SpoofingGHSA-vhxc-r7v8-2xrw published
Feb 27, 2026 by kovidgoyalModerate -
HTTP Response Header InjectionGHSA-5fpj-fxw7-8grw published
Feb 27, 2026 by kovidgoyalModerate -
Path Traversal Leading to Arbitrary File Write and Potentially Code ExecutionGHSA-vmfh-7mr7-pp2w published
Feb 20, 2026 by kovidgoyalCritical -
Path Traversal Leading to Arbitrary File Write and Potentially Code ExecutionGHSA-72ch-3hqc-pgmp published
Feb 20, 2026 by kovidgoyalCritical