MEDIUM5.4
PYSEC-2026-1229
Improper Access Control in janeczku/calibre-web
Quick fix
PYSEC-2026-1229 — calibreweb: upgrade to the fixed version with the command below.
pip install --upgrade 'calibreweb>=0.6.15'Details
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary permissions to create a public shelf. This issue can lead to unauthorized actions being performed by users.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-3987[ADVISORY]
- https://github.com/janeczku/calibre-web/commit/bcdc97641447965af486964537f3821f47b28874[WEB]
- https://github.com/janeczku/calibre-web[PACKAGE]
- https://huntr.com/bounties/29fcc091-87b6-43bc-ab4b-3c0bec3f71df[WEB]
- https://pypi.org/project/calibreweb[PACKAGE]
- https://github.com/advisories/GHSA-fj5v-w2jp-wqvj[ADVISORY]