PT-2025-30699 · Unknown · Autocaliweb+1

Published

2025-07-24

·

Updated

2025-08-05

·

CVE-2025-7404

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Calibre Web versions 0.6.24 Autocaliweb versions 0.7.0 through 0.7.0
Description Calibre Web and Autocaliweb are susceptible to a blind OS command injection issue due to improper neutralization of special elements used in OS commands. This allows for potential unauthorized execution of commands on the underlying operating system.
Recommendations Update Calibre Web to a version later than 0.6.24. Update Autocaliweb to version 0.7.1 or later.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-7404
GHSA-QC4J-V7H6-XR5H

Affected Products

Autocaliweb
Calibre-Web