← Vulnerability feed

Vulnerability record · CVE-2024-6781 · published 6 August 2024

CVE-2024-6781: Calibre path traversal allows unauthenticated arbitrary file read

Calibre Ebook · Calibre

Calibre 7.14.0 and earlier contain a path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files. Because Calibre is commonly run as a local content server, exposed instances can leak any file the process can access. The vendor has published a patch commit.

7.5 CVSS 3.1 High EPSS 62% · top 0.8% CWE-22 · Path traversal
7.5CVSS 3.1 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable arbitrary file read with a high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is documented.

What it is

Calibre 7.14.0 and earlier contain a path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files. Because Calibre is commonly run as a local content server, exposed instances can leak any file the process can access. The vendor has published a patch commit.

Impact

An attacker gains read access to arbitrary files on the host, including configuration, credential and user data files readable by the Calibre process. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), consistent with the CVSS vector. The description does not specify the exact endpoint, so the precise request path is not documented in this record.

Exploitation

Not listed in CISA KEV and no public exploit reference is tagged, but EPSS is high at 0.624 (99th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade Calibre to a version containing the patch commit bcd0ab12c41a887f8290a9b56e46c3a29038d9c4 or later.
  • Do not expose the Calibre content server to untrusted networks; bind it to localhost or restrict access via firewall or reverse proxy.
  • Run Calibre under a low-privilege account with access limited to the library directory.
  • Monitor vendor advisories and the Star Labs advisory for updated guidance.

Detection

  • Inspect web server or Calibre access logs for traversal sequences such as ../ or encoded variants in request paths.
  • Alert on requests to the Calibre content server from unexpected source addresses or at unusual rates.
  • Audit file access by the Calibre process for reads outside the library directory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-6781 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2011-4124Calibre-ebook calibre improper input validation vulnerabilityInput validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.EPSS 2.3%9.8CVE-2011-4125Calibre-ebook calibre untrusted search path vulnerabilityA untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any progra…EPSS 2.3%9.3CVE-2026-26065Calibre-ebook calibre path traversal vulnerabilitycalibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path …EPSS 0.56%9.3CVE-2026-26064Calibre-ebook calibre path traversal vulnerabilitycalibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversa…EPSS 0.85%8.6CVE-2026-25635Calibre-ebook calibre path traversal vulnerabilitycalibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows arbitrary file writes anywhere…EPSS 0.36%8.2CVE-2026-33206Calibre-ebook calibre relative path traversal vulnerabilitycalibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnera…EPSS 0.22%8.2CVE-2026-30853Calibre-ebook calibre path traversal vulnerabilitycalibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability i…EPSS 0.19%8.1CVE-2011-4126Calibre-ebook calibre toctou race condition vulnerabilityRace condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2024-6781), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.