CVE-2026-26064 | kovidgoyal calibre up to 9.2.x utils/zipfile.py ZipFile.extractall path traversal (GHSA-72ch-3hqc-pgmp)
A vulnerability marked as critical has been reported in kovidgoyal calibre up to 9.2.x. Affected is the function ZipFile.extractall of the file utils/zipfile.py. This manipulation causes path traversal.
This vulnerability is handled as CVE-2026-26064. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.