CVE-2026-30853
CVE-2026-30853 is a medium-severity vulnerability in Calibre-ebook Calibre with a CVSS 3.x base score of 5.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Medium (CVSS 3.x base score 5.0)
- EPSS exploit prediction: 0% (8th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-12069
- Weakness: CWE-22
- Affected product: Calibre-ebook Calibre
- Published:
- Last modified:
Description
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability in the RocketBook (.rb) input plugin (src/calibre/ebooks/rb/reader.py) allows an attacker to write arbitrary files to any path writable by the calibre process when a user opens or converts a crafted .rb file. This is the same bug class fixed in CVE-2026-26065 for the PDB readers, but the fix was never applied to the RB reader. This vulnerability is fixed in 9.5.0.
Frequently asked questions
- What is CVE-2026-30853?
- calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability in the RocketBook (.rb) input plugin (src/calibre/ebooks/rb/reader.py) allows an attacker to write arbitrary files to any path writable by the calibre process when a user opens or converts a crafted .rb file. This is the same bug class fixed in CVE-2026-26065 for the PDB readers, but the fix was never applied to the RB reader. This vulnerability is fixed in 9.5.0.
- How severe is CVE-2026-30853?
- CVE-2026-30853 has a CVSS 3.x base score of 5.0, rated medium severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is none, integrity low, and availability low.
- Is CVE-2026-30853 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (8th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-30853?
- CVE-2026-30853 affects Calibre-ebook Calibre. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-30853?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-30853 have an EU (EUVD) identifier?
- Yes. CVE-2026-30853 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-12069.
- When was CVE-2026-30853 published?
- CVE-2026-30853 was published on 2026-03-13 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:*
More vulnerabilities in Calibre-ebook Calibre
- CVE-2011-4125 — Critical (CVSS 9.8): A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of…
- CVE-2011-4124 — Critical (CVSS 9.8): Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and…
- CVE-2026-26065 — High (CVSS 8.8): calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and…
- CVE-2026-26064 — High (CVSS 8.8): calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and…
- CVE-2026-25635 — High (CVSS 8.6): calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows…
- CVE-2026-25636 — High (CVSS 8.2): calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows…
All CVEs affecting Calibre-ebook Calibre →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.