NONE · 0

CVE-2025-64486

calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesyste...

Vulnerability Description

calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesystem when viewing or converting a malicious FictionBook file. This can be leveraged to achieve arbitrary code execution. This issue is fixed in version 8.14.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-64486?

CVE-2025-64486 is a documented vulnerability. calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary assets in FB2 files, allowing an attacker to write arbitrary files on the filesyste...

How severe is CVE-2025-64486?

CVSS scoring is not yet available for CVE-2025-64486. Check NVD for updates.

Is there a patch for CVE-2025-64486?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.