CRITICAL9.8
PYSEC-2026-305
SQL injection in calibreweb
Quick fix
PYSEC-2026-305 — calibreweb: upgrade to the fixed version with the command below.
pip install --upgrade 'calibreweb>=0.6.18'Details
Calibre-Web before 0.6.18 allows user table SQL Injection.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-30765[ADVISORY]
- https://github.com/janeczku/calibre-web[PACKAGE]
- https://github.com/janeczku/calibre-web/blob/master/SECURITY.md[WEB]
- https://github.com/janeczku/calibre-web/releases/tag/0.6.18[WEB]
- https://pypi.org/project/calibreweb[PACKAGE]
- https://github.com/advisories/GHSA-8ppf-x4gr-2x7g[ADVISORY]