CVE-2025-71389
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.
Ver en NVDAnálisis
Cal.com presenta una vulnerabilidad de ejecución remota de código (RCE) sin autenticación que permite a un atacante tomar control total del servidor mediante peticiones manipuladas a los React Server Components. El fallo reside en una dependencia de Next.js que deserializa entrada no confiable durante el procesamiento en el servidor, comprometiendo la infraestructura sin necesidad de interacción del usuario. Es fundamental actualizar a la versión 5.9.9 o superior para mitigar este riesgo de severidad máxima.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-94EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.