Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

kovidgoyal — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting kovidgoyal. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kovidgoyal develops open-source software primarily used for web scraping and automation, with applications in data extraction and process automation. Historically, their code has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and insecure deserialization. The researcher has disclosed multiple critical flaws affecting various projects, including some that allowed attackers to execute arbitrary code or bypass security controls. While no major public security incidents have been directly attributed to kovidgoyal's work, their CVE history indicates a pattern of security weaknesses that require careful mitigation when implementing their tools in production environments.

Found 14 results / 22 Clear Filters
Top products by kovidgoyal: calibre kitty
CVE ID Title CVSS Severity Published
CVE-2026-73249 calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification — calibre CWE-862 7.5 High 2026-08-11
CVE-2026-73248 calibre: Bypass of Python template restrictions via nested `template()` leading to RCE — calibre CWE-94 8.5 High 2026-08-11
CVE-2026-53511 calibre: Arbitrary Code Execution in Template Formatter via Book Metadata — calibre CWE-94 8.5 High 2026-07-07
CVE-2026-33206 calibre has a path traversal vulnerability — calibre CWE-23 9.8 - 2026-03-27
CVE-2026-33205 calibre has Server-Side Request Forgery in ebook viewer backend — calibre CWE-918 8.6 - 2026-03-27
CVE-2026-30853 calibre has a Path Traversal Leading to Arbitrary File Write — calibre CWE-22 5.0 Medium 2026-03-13
CVE-2026-27824 calibre has IP Ban Bypass via X-Forwarded-For Header Spoofing — calibre CWE-307 5.3 Medium 2026-02-27
CVE-2026-27810 calibre Vulnerable to HTTP Response Header Injection — calibre CWE-113 6.4 Medium 2026-02-27
CVE-2026-26065 calibre: Path Traversal can Lead to Arbitrary File Write and Potential Code Execution — calibre CWE-22 8.8 - 2026-02-20
CVE-2026-26064 calibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code Execution — calibre CWE-22 8.8 - 2026-02-20
CVE-2026-25731 Calibre Affected by Arbitrary Code Execution via Server-Side Template Injection in Calibre HTML Export — calibre CWE-1336 7.8 High 2026-02-06
CVE-2026-25635 calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution — calibre CWE-22 8.6 High 2026-02-06
CVE-2026-25636 calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execution — calibre CWE-22 8.2 High 2026-02-06
CVE-2025-64486 calibre is vulnerable to arbitrary code execution when opening FB2 files — calibre CWE-73 7.8 - 2025-11-07

This page lists every published CVE security advisory associated with kovidgoyal. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.