CRITICAL9.8
PYSEC-2026-307
calibre-web is vulnerable to Business Logic Errors
Quick fix
PYSEC-2026-307 — calibreweb: upgrade to the fixed version with the command below.
pip install --upgrade 'calibreweb>=0.6.15'Details
calibre-web is vulnerable to Business Logic Errors
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-4171[ADVISORY]
- https://github.com/janeczku/calibre-web/commit/3e0d8763c377d2146462811e3e4ccf13f0d312ce[WEB]
- https://github.com/janeczku/calibre-web[PACKAGE]
- https://huntr.dev/bounties/1117f439-133c-4563-afb2-6cd80607bd5c[WEB]
- https://pypi.org/project/calibreweb[PACKAGE]
- https://github.com/advisories/GHSA-xp7p-3gx7-j6wx[ADVISORY]