PT-2025-30699 · Unknown · Calibre-Web+1

CVE-2025-7404

·

Published

2025-07-24

·

Updated

2026-07-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Calibre Web versions 0.6.24 Autocaliweb versions 0.7.0 through 0.7.0
Description Calibre Web and Autocaliweb are susceptible to a blind OS command injection issue due to improper neutralization of special elements used in OS commands. This allows for potential unauthorized execution of commands on the underlying operating system.
Recommendations Update Calibre Web to a version later than 0.6.24. Update Autocaliweb to version 0.7.1 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7404
GHSA-QC4J-V7H6-XR5H
PYSEC-2026-1235

Affected Products

Autocaliweb
Calibre-Web