Bug 2497845 (CVE-2026-53511)

Summary: CVE-2026-53511 calibre: Calibre: Arbitrary code execution via malicious e-book file processing
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in calibre, an e-book manager. This vulnerability allows a remote attacker to execute unauthorized code on a user's system. By creating a specially crafted e-book file (such as EPUB, OPF, or PDF) with malicious metadata, an attacker can trigger the execution of arbitrary Python code when the file's metadata is processed by calibre. This could lead to a complete compromise of the affected system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2498951    
Bug Blocks:    

Description OSIDB Bzimport 2026-07-07 21:02:14 UTC
calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read by calibre, including through Add books or Edit books, by embedding a custom column definition with a python: template in calibre:user_metadata that is passed unsanitized to exec() in the template formatter. This issue is fixed in version 9.10.0.