Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2025-71389

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.

View on NVD

Analysis

Cal.com presenta una vulnerabilidad de ejecución remota de código (RCE) sin autenticación que permite a un atacante tomar control total del servidor mediante peticiones manipuladas a los React Server Components. El fallo reside en una dependencia de Next.js que deserializa entrada no confiable durante el procesamiento en el servidor, comprometiendo la infraestructura sin necesidad de interacción del usuario. Es fundamental actualizar a la versión 5.9.9 o superior para mitigar este riesgo de severidad máxima.

Relevant roles

ReactJavascriptTypescriptBackendFrontendCyberSecurity

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-94

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.

Published: 7/23/2026, 10:16:51 PM
Last modified: 7/23/2026, 10:16:51 PM

References

HomeEventsBlogResourcesTeam