Vulnerability record · CVE-2024-6781 · published 6 August 2024
CVE-2024-6781: Calibre path traversal allows unauthenticated arbitrary file read
Calibre Ebook · Calibre
Calibre 7.14.0 and earlier contain a path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files. Because Calibre is commonly run as a local content server, exposed instances can leak any file the process can access. The vendor has published a patch commit.
Description
Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable arbitrary file read with a high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is documented.
What it is
Calibre 7.14.0 and earlier contain a path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files. Because Calibre is commonly run as a local content server, exposed instances can leak any file the process can access. The vendor has published a patch commit.
Impact
An attacker gains read access to arbitrary files on the host, including configuration, credential and user data files readable by the Calibre process. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), consistent with the CVSS vector. The description does not specify the exact endpoint, so the precise request path is not documented in this record.
Exploitation
Not listed in CISA KEV and no public exploit reference is tagged, but EPSS is high at 0.624 (99th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade Calibre to a version containing the patch commit bcd0ab12c41a887f8290a9b56e46c3a29038d9c4 or later.
- Do not expose the Calibre content server to untrusted networks; bind it to localhost or restrict access via firewall or reverse proxy.
- Run Calibre under a low-privilege account with access limited to the library directory.
- Monitor vendor advisories and the Star Labs advisory for updated guidance.
Detection
- Inspect web server or Calibre access logs for traversal sequences such as ../ or encoded variants in request paths.
- Alert on requests to the Calibre content server from unexpected source addresses or at unusual rates.
- Audit file access by the Calibre process for reads outside the library directory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/kovidgoyal/calibre/commit/bcd0ab12c41a887f8290a9b56e46c3a29038d9c4 | Patch |
| https://starlabs.sg/advisories/24/24-6781/ | Third Party Advisory |
Track CVE-2024-6781 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-6781), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.