Beveiligingsadvies

CVE-2026-53511

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-07 20:46:49
Laatst bijgewerkt 2026-08-18 07:16:16
Toegewezen door GitHub_M
CVSS-score 8.5
Status PUBLISHED

Beschrijving

calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read by calibre, including through Add books or Edit books, by embedding a custom column definition with a python: template in calibre:user_metadata that is passed unsanitized to exec() in the template formatter. This issue is fixed in version 9.10.0.