MEDIUM5.4
PYSEC-2026-620
calibre-web is vulnerable to Cross-site Scripting
Quick fix
PYSEC-2026-620 — calibreweb: upgrade to the fixed version with the command below.
pip install --upgrade 'calibreweb>=0.6.15'Details
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-4170[ADVISORY]
- https://github.com/janeczku/calibre-web/commit/7ad419dc8c12180e842a82118f4866ac3d074bc5[WEB]
- https://github.com/janeczku/calibre-web[WEB]
- https://huntr.dev/bounties/ff395101-e392-401d-ab4f-579c63fbf6a0[WEB]
- https://pypi.org/project/calibreweb[PACKAGE]
- https://github.com/advisories/GHSA-wrp6-9w7f-3wxg[ADVISORY]