๐Ÿ” CVE Alert

CVE-2026-73248

UNKNOWN 0.0

calibre: Bypass of Python template restrictions via nested `template()` leading to RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inherit allow_python_templates=False, allowing a nested python: template to reach compile_python_template and execute arbitrary Python code when the file is opened or imported. This issue is fixed in version 9.12.0.

CWE CWE-94 CWE-95
Vendor kovidgoyal
Product calibre
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for kovidgoyal calibre

Be the first to know when new unknown vulnerabilities affecting kovidgoyal calibre are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kovidgoyal / calibre
< 9.12.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4f7g-rjfp-hmvx github.com: https://github.com/kovidgoyal/calibre/commit/dac9990458374a81a5372a768bba6527d965aac8 github.com: https://github.com/kovidgoyal/calibre/releases/tag/v9.12.0