CVE-2026-73248

NameCVE-2026-73248
Descriptioncalibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inherit allow_python_templates=False, allowing a nested python: template to reach compile_python_template and execute arbitrary Python code when the file is opened or imported. This issue is fixed in version 9.12.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
calibre (PTS)bullseye5.12.0+dfsg-1+deb11u2vulnerable
bullseye (security)5.12.0+dfsg-1+deb11u5vulnerable
bookworm6.13.0+repack-2+deb12u9vulnerable
trixie8.5.0+ds-1+deb13u3vulnerable
forky, sid9.13.0+ds+~0.10.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
calibresource(unstable)9.12.0+ds+~0.10.6-1

Notes

https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4f7g-rjfp-hmvx
Fixed by: https://github.com/kovidgoyal/calibre/commit/dac9990458374a81a5372a768bba6527d965aac8 (v9.12.0)

Search for package or bug name: Reporting problems