NIXPKGS-2026-0155
GitHub issue
published on 7 Feb 2026
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
4 packages
- calibre-web
- pkgsRocm.calibre
- calibre-no-speech
- pkgsRocm.calibre-no-speech
- @LeSuisse accepted
- @LeSuisse published on GitHub
Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML Export
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This vulnerability is fixed in 9.2.0.
References
-
https://github.com/kovidgoyal/calibre/security/advisories/GHSA-xrh9-w7qx-3gcc x_refsource_CONFIRM
Affected products
calibre
- ==< 9.2.0
Package maintainers
-
@pSub Pascal Wittmann <mail@pascal-wittmann.de>