Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

kovidgoyal — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting kovidgoyal. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kovidgoyal develops open-source software primarily used for web scraping and automation, with applications in data extraction and process automation. Historically, their code has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and insecure deserialization. The researcher has disclosed multiple critical flaws affecting various projects, including some that allowed attackers to execute arbitrary code or bypass security controls. While no major public security incidents have been directly attributed to kovidgoyal's work, their CVE history indicates a pattern of security weaknesses that require careful mitigation when implementing their tools in production environments.

Top products by kovidgoyal: calibre kitty
CVE ID Title CVSS Severity Published
CVE-2026-73249 calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification — calibre CWE-862 7.5 High 2026-08-11
CVE-2026-73248 calibre: Bypass of Python template restrictions via nested `template()` leading to RCE — calibre CWE-94 8.5 High 2026-08-11
CVE-2026-72913 Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequences — kitty CWE-77 7.3 High 2026-08-10
CVE-2026-53511 calibre: Arbitrary Code Execution in Template Formatter via Book Metadata — calibre CWE-94 8.5 High 2026-07-07
CVE-2026-54057 Kitty vulnerable to command injection via unsanitized OSC 21 query reply — kitty CWE-94 - - 2026-06-12
CVE-2026-54056 Kitty has an arbitrary file overwrite via symlink following in `kitten dnd` remote drop staging — kitty CWE-59 7.6 High 2026-06-12
CVE-2026-54055 Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmission Protocol — kitty CWE-59 5.0 Medium 2026-06-12
CVE-2026-42851 @kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCE — kitty CWE-94 7.8 High 2026-06-12
CVE-2026-42850 Kitty has a shell command injection — kitty CWE-77 - - 2026-06-12
CVE-2026-33642 Kitty has a Heap Buffer Over-Read/Write via Integer Overflow in compose_rectangles Bounds Check — kitty CWE-190 9.9 Critical 2026-05-19
CVE-2026-33633 Kitty has a Heap Buffer Overflow in its Graphics Protocol Handler — kitty CWE-122 7.5 High 2026-05-19
CVE-2026-33206 calibre has a path traversal vulnerability — calibre CWE-23 9.8 - 2026-03-27
CVE-2026-33205 calibre has Server-Side Request Forgery in ebook viewer backend — calibre CWE-918 8.6 - 2026-03-27
CVE-2026-30853 calibre has a Path Traversal Leading to Arbitrary File Write — calibre CWE-22 5.0 Medium 2026-03-13
CVE-2026-27824 calibre has IP Ban Bypass via X-Forwarded-For Header Spoofing — calibre CWE-307 5.3 Medium 2026-02-27
CVE-2026-27810 calibre Vulnerable to HTTP Response Header Injection — calibre CWE-113 6.4 Medium 2026-02-27
CVE-2026-26065 calibre: Path Traversal can Lead to Arbitrary File Write and Potential Code Execution — calibre CWE-22 8.8 - 2026-02-20
CVE-2026-26064 calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Execution — calibre CWE-22 8.8 - 2026-02-20
CVE-2026-25731 Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML Export — calibre CWE-1336 7.8 High 2026-02-06
CVE-2026-25635 calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution — calibre CWE-22 8.6 High 2026-02-06
CVE-2026-25636 calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execution — calibre CWE-22 8.2 High 2026-02-06
CVE-2025-64486 calibre is vulnerable to arbitrary code execution when opening FB2 files — calibre CWE-73 7.8 - 2025-11-07

This page lists every published CVE security advisory associated with kovidgoyal. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.