CVE-2026-25635 | kovidgoyal calibre up to 9.1.x CHM Reader path traversal (EUVD-2026-5596 / Nessus ID 298303)
A vulnerability was found in kovidgoyal calibre up to 9.1.x. It has been classified as critical. This issue affects some unknown processing of the component CHM Reader. This manipulation causes path traversal.
This vulnerability is registered as CVE-2026-25635. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.