CVE-2026-33206
⚪ Do wiadomości
Wykorzystanie podatności w Calibre pozwala na wczytanie dowolnych plików z systemu.
CVSS
6.3
EPSS
0.0%
Exploit
poc
Vendor
calibre-ebook
Opis źródłowy (NVD)
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar text-based files allowing an attacker to include arbitrary files from the file system into the converted book. Additionally, missing authentication and server-side request forgery in the background-image endpoint in the ebook reader web view allow the files to be exfiltrated without additional interaction. Version 9.6.0 contains a fix.
exploit path-traversal ssrf
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.0% |
| Opublikowano (NVD) | 2026-03-27 15:16:54 UTC |
| Ostatnia modyfikacja (NVD) | 2026-03-30 20:46:25 UTC |
Referencje
- https://github.com/kovidgoyal/calibre/security/advisories/GHSA-h3p4-m74f-43g6 (security-advisories@github.com) [Exploit, Vendor Advisory]