icon

We found results for “

CVE-2025-64486

Good to know:

icon
icon

Date: November 7, 2025

calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesystem when viewing or converting a malicious FictionBook file. This can be leveraged to achieve arbitrary code execution. This issue is fixed in version 8.14.0.

Severity Score

Severity Score

Weakness Type (CWE)

External Control of File Name or Path

CWE-73

Top Fix

icon

Upgrade Version

Upgrade to version https://github.com/kovidgoyal/calibre.git - v8.14.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us