{"id":"CVE-2026-73248","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-73248","summary":"calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and…","details":"calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inherit allow_python_templates=False, allowing a nested python: template to reach compile_python_template and execute arbitrary Python code when the file is opened or imported. This issue is fixed in version 9.12.0.","published":"2026-08-11T22:19:05.553","modified":"2026-08-11T22:19:05.553","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/kovidgoyal/calibre/commit/dac9990458374a81a5372a768bba6527d965aac8","label":"kovidgoyal/calibre@dac9990"},"references":[{"type":"WEB","url":"https://github.com/kovidgoyal/calibre/commit/dac9990458374a81a5372a768bba6527d965aac8"},{"type":"WEB","url":"https://github.com/kovidgoyal/calibre/releases/tag/v9.12.0"},{"type":"WEB","url":"https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4f7g-rjfp-hmvx"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-11T22:19:05.553"}}