CVE-2025-71389
CRITICAL
10.0
CVSS 3.1
Description
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| calcom | cal.diy | — | 0 < 5.9.9, 5.9.9 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-94 | cna | Improper Control of Generation of Code ('Code Injection') |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
| 10.0 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
References (4)
- GitHub Security Advisory (GHSA-qjx2-5xqp-cpf4) https://github.com/calcom/cal.diy/security/advisories/GHSA-qjx2-5xqp-cpf4
- Patch (PR #25592) https://github.com/calcom/cal.diy/pull/25592
- Upstream Next.js advisory (CVE-2025-55182) https://github.com/advisories/GHSA-9qr9-h5gf-34mp
- VulnCheck Advisory: Cal.com before 5.9.9 Remote Code Execution via RSC https://www.vulncheck.com/advisories/cal-com-before-remote-code-execution-via-rsc