Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22546 | Calibre Web and Autocaliweb have OS Command Injection vulnerability |
Github GHSA |
GHSA-qc4j-v7h6-xr5h | Calibre Web and Autocaliweb have OS Command Injection vulnerability |
Fri, 16 Jan 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gelbphoenix
Gelbphoenix autocaliweb Janeczku Janeczku calibre-web |
|
| CPEs | cpe:2.3:a:gelbphoenix:autocaliweb:0.7.0:*:*:*:*:*:*:* cpe:2.3:a:janeczku:calibre-web:0.6.24:*:*:*:*:*:*:* |
|
| Vendors & Products |
Gelbphoenix
Gelbphoenix autocaliweb Janeczku Janeczku calibre-web |
|
| Metrics |
cvssV3_1
|
Fri, 25 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Jul 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1. | |
| Title | Calibre Web 0.6.24 & Autocaliweb 0.7.0 - Blind C | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-07-25T19:07:25.482Z
Reserved: 2025-07-10T04:15:11.925Z
Link: CVE-2025-7404
Updated: 2025-07-25T13:33:41.082Z
Status : Analyzed
Published: 2025-07-24T21:15:52.617
Modified: 2026-01-16T14:48:48.660
Link: CVE-2025-7404
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA