{"id":"CVE-2025-7404","aliases":["GHSA-qc4j-v7h6-xr5h","PYSEC-2026-1235"],"title":"Calibre Web and Autocaliweb have OS Command Injection vulnerability","summary":"Calibre Web and Autocaliweb have OS Command Injection vulnerability","severity":"medium","vendor":"calibreweb","product":"calibreweb","ecosystem":"pip","affected":["calibreweb <= 0.6.24"],"published":"2025-07-24","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-qc4j-v7h6-xr5h","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-7404"},{"url":"https://fluidattacks.com/advisories/kino"},{"url":"https://github.com/gelbphoenix/autocaliweb"},{"url":"https://github.com/janeczku/calibre-web"}],"tags":["osv","pip","exploit-available"],"epss":0.02752,"epssPercentile":0.85495,"ingestedAt":"2026-07-08T18:25:52.392Z","exploits":{"github":1,"githubRepos":["https://github.com/mind2hex/CVE-2025-7404-CalibreWeb-0.6.24-BlindCommandInjection"],"checkedAt":"2026-09-21T15:27:36.493Z"},"exploitAvailable":true,"slug":"CVE-2025-7404","body":"## Overview\n\nImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.\n\n## Affected packages\n\n- `calibreweb <= 0.6.24`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":27.5,"likelihood":0.6,"exploitation":12,"ransomware":0},"changes":[{"seq":4870,"id":"CVE-2025-7404","ts":1788887212703,"field":"exploit_available","old":"false","new":"true"},{"seq":3753,"id":"CVE-2025-7404","ts":1788886329317,"field":"exploit_available","old":"true","new":"false"},{"seq":2598,"id":"CVE-2025-7404","ts":1788883010394,"field":"exploit_available","old":"false","new":"true"},{"seq":1627,"id":"CVE-2025-7404","ts":1788882410689,"field":"exploit_available","old":"true","new":"false"},{"seq":738,"id":"CVE-2025-7404","ts":1788881847910,"field":"exploit_available","old":"false","new":"true"}]}