Remote Code Execution Vulnerability in Cal.com by Cal.com
CVE-2025-71389
10CRITICAL
What is CVE-2025-71389?
The Cal.com platform prior to version 5.9.9 contains a significant vulnerability allowing unauthenticated remote code execution. This arises from a deserialization issue in how the server handles React Server Components (RSC) requests, which can be exploited by an attacker sending specially crafted inputs. As a result, arbitrary code may be executed on the server without the need for authentication or user interaction. This vulnerability is linked to an upstream issue found in Next.js, identified as CVE-2025-55182, and has been addressed in the latest patch update.
Affected Version(s)
cal.diy 0 < 5.9.9
cal.diy 5.9.9
