Security Advisory

CVE-2026-53511

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-07 20:46:49
Last updated 2026-07-09 03:55:49
Assigner GitHub_M
CVSS score 8.5
State PUBLISHED

Description

calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read by calibre, including through Add books or Edit books, by embedding a custom column definition with a python: template in calibre:user_metadata that is passed unsanitized to exec() in the template formatter. This issue is fixed in version 9.10.0.