VDB
Sign up
—

PYSEC-2026-1235

Calibre Web and Autocaliweb have OS Command Injection vulnerability

Details

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/calibreweb
Introduced in: 0

No fixed version published yet for calibreweb (pip). Pin to a known-safe version or switch to an alternative.

References