Stored Cross-Site Scripting Vulnerability in Cal.com Cal.diy Product
CVE-2026-57858
What is CVE-2026-57858?
The Cal.com Cal.diy product, specifically versions 2.1.1 through 6.2.0, has a stored cross-site scripting (XSS) vulnerability found within the BookingPageTagManager component. This issue enables authenticated event owners to inject malicious JavaScript via an unvalidated analytics tracking ID. When exploited, the entered payload can close the inline script string literal to execute arbitrary scripts in the browser of anyone visiting the public booking page. This could lead to various malicious activities such as session cookie theft, unauthorized requests, and even allow attackers to propagate further by utilizing cross-site request forgery (CSRF) vulnerabilities, making it possible to embed malicious payloads into additional events.
Affected Version(s)
Cal.com Self-Hosted (Cal.diy) 2.1.1 <= 6.2.0
