Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2025-71389

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.

Ver en NVD

Análisis

Cal.com presenta una vulnerabilidad de ejecución remota de código (RCE) sin autenticación que permite a un atacante tomar control total del servidor mediante peticiones manipuladas a los React Server Components. El fallo reside en una dependencia de Next.js que deserializa entrada no confiable durante el procesamiento en el servidor, comprometiendo la infraestructura sin necesidad de interacción del usuario. Es fundamental actualizar a la versión 5.9.9 o superior para mitigar este riesgo de severidad máxima.

Roles relevantes

ReactJavascriptTypescriptBackendFrontendCyberSecurity

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-94

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.

Publicada: 23/7/2026, 22:16:51
Última modificación: 23/7/2026, 22:16:51

Referencias

InicioEventosBlogRecursosEquipo