Open Redirect Vulnerability in Calcom Conferencing OAuth Callback
CVE-2026-63768
Key Information:
Badges
What is CVE-2026-63768?
The cal.diy application, from Calcom, is susceptible to an open redirect vulnerability located in the conferencing OAuth callback endpoint. This flaw allows attackers to craft malicious state parameters that can redirect unsuspecting users from a legitimate domain to arbitrary URLs controlled by the attacker. By exploiting the unsigned state parameter and the onErrorReturnTo field, attackers can facilitate phishing attacks, potentially compromising the information and security of users. Users of the service should ensure they are using the latest version to mitigate the risk associated with this vulnerability.
Affected Version(s)
cal.diy 0 <= 6.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
