VulnerabilityAnalyzed
CVE-2025-7404
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before…
MEDIUM 5.9EPSS 2.75%
Does this matter?
Lower severity and a low EPSS score (2.75%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.
- CVSS 4.0
- 5.9 MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 2.75% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- gelbphoenix/autocaliweb · janeczku/calibre-web
- Source
- help@fluidattacks.com
References
- https://fluidattacks.com/advisories/kinoExploit, Third Party Advisory
- https://github.com/gelbphoenix/autocaliwebRelease Notes
- https://github.com/janeczku/calibre-webProduct
- https://fluidattacks.com/advisories/kinoExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.