The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10187.json"