CVE-2026-73248
calibre: Bypass of Python template restrictions via nested `template()` leading to RCE
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inherit allow_python_templates=False, allowing a nested python: template to reach compile_python_template and execute arbitrary Python code when the file is opened or imported. This issue is fixed in version 9.12.0.
| CWE | CWE-94 CWE-95 |
| Vendor | kovidgoyal |
| Product | calibre |
| Published | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for kovidgoyal calibre
Be the first to know when new unknown vulnerabilities affecting kovidgoyal calibre are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
kovidgoyal / calibre
< 9.12.0