Remote Code Execution Vulnerability in Cal.com by Cal.com
CVE-2025-71389

10CRITICAL

Key Information:

Vendor

Calcom

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2025-71389?

The Cal.com platform prior to version 5.9.9 contains a significant vulnerability allowing unauthenticated remote code execution. This arises from a deserialization issue in how the server handles React Server Components (RSC) requests, which can be exploited by an attacker sending specially crafted inputs. As a result, arbitrary code may be executed on the server without the need for authentication or user interaction. This vulnerability is linked to an upstream issue found in Next.js, identified as CVE-2025-55182, and has been addressed in the latest patch update.

Affected Version(s)

cal.diy 0 < 5.9.9

cal.diy 5.9.9

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.