The fact
The first flaw enables directory traversal through Markdown images, while the second allows Server-Side Request Forgery via the Background-image endpoint.
These vulnerabilities expose Calibre servers to unauthorized access and malicious requests from within the network.
Click the link to read an article on the topic: