CVE-2025-64486

CRITICAL

calibre <8.13.0 - Code Injection

Title source: llm
STIX 2.1

Description

calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesystem when viewing or converting a malicious FictionBook file. This can be leveraged to achieve arbitrary code execution. This issue is fixed in version 8.14.0.

Scores

CVSS v4 9.3
EPSS 0.0004
EPSS Percentile 11.7%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-73
Status published
Products (1)
kovidgoyal/calibre < 8.14.0
Published Nov 08, 2025
Tracked Since Feb 18, 2026