CVE Feed

    Dashboard / CVE / CVE-2025-71389

    CVE-2025-71389

    Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.

    Published:Jul 23, 2026
    Last Modified:Jul 28, 2026
    EPS:Jul 23, 2026
    EPSS Score:0.00928
    CVSS Score:10

    Affected Products

    Vendor
    Cal
    Product
    Cal.com
    Vendor
    Calcom
    Product
    Cal.diy

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High