CVE-2026-33206 is a medium-severity path traversal and Server-Side Request Forgery (SSRF) vulnerability affecting Calibre e-book manager versions prior to 9.6.0. This flaw allows an attacker to craft malicious text-based files that, when processed, can include arbitrary local files into a converted e-book. The vulnerability further enables exfiltration of these included files via an unauthenticated background-image endpoint in the e-book reader web view, posing a high confidentiality risk (CVSS 6.3, Medium). While user interaction is required to trigger the initial path traversal, there is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.6.0CPE matchmatch criteria | cpe:2.3:a:calibre-ebook:calibre:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.