—
PYSEC-2026-1235
Calibre Web and Autocaliweb have OS Command Injection vulnerability
Details
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/calibreweb
Introduced in:
0No fixed version published yet for calibreweb (pip). Pin to a known-safe version or switch to an alternative.