CVE-2025-7404

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gelbphoenix:autocaliweb:0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:janeczku:calibre-web:0.6.24:*:*:*:*:*:*:*

History

16 Jan 2026, 14:48

Type Values Removed Values Added
References () https://fluidattacks.com/advisories/kino - () https://fluidattacks.com/advisories/kino - Exploit, Third Party Advisory
References () https://github.com/gelbphoenix/autocaliweb - () https://github.com/gelbphoenix/autocaliweb - Release Notes
References () https://github.com/janeczku/calibre-web - () https://github.com/janeczku/calibre-web - Product
Summary
  • (es) Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('inyección de comando del sistema operativo') en Calibre Web, Autocaliweb permite la inyección ciega de comandos del sistema operativo. Este problema afecta a Calibre Web: 0.6.24 (Nicolette); Autocaliweb: desde 0.7.0 antes de 0.7.1.
First Time Janeczku calibre-web
Gelbphoenix
Janeczku
Gelbphoenix autocaliweb
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:gelbphoenix:autocaliweb:0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:janeczku:calibre-web:0.6.24:*:*:*:*:*:*:*

25 Jul 2025, 19:15

Type Values Removed Values Added
References () https://fluidattacks.com/advisories/kino - () https://fluidattacks.com/advisories/kino -

24 Jul 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-24 21:15

Updated : 2026-01-16 14:48


NVD link : CVE-2025-7404

Mitre link : CVE-2025-7404

CVE.ORG link : CVE-2025-7404


JSON object : View

Products Affected

janeczku

  • calibre-web

gelbphoenix

  • autocaliweb
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')