Low severityOSV Advisory· Published Dec 2, 2025· Updated Dec 2, 2025
CVE-2025-65858
CVE-2025-65858
Description
A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the 'username' field during user creation. The payload is stored unsanitized and later executed when the /ajax/listusers endpoint is accessed.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
calibrewebPyPI | <= 0.6.25 | — |
Affected products
1- Range: 0.6.0, 0.6.10, 0.6.11, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.