CVE-2025-71389: Cal.com before 5.9.9 Remote Code Execution via RSC
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
calcom/cal.diyto a version that resolves this vulnerability.Fixed in 5.9.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2025-55182
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71389?
CVE-2025-71389 has a critical severity rating of 10.
How do I fix CVE-2025-71389?
To mitigate CVE-2025-71389, upgrade Cal.com to version 5.9.9 or later.
What type of vulnerability is CVE-2025-71389?
CVE-2025-71389 is a remote code execution vulnerability caused by code injection.
What can attackers do with CVE-2025-71389?
Attackers can exploit CVE-2025-71389 to execute arbitrary code on the server.
Which software is affected by CVE-2025-71389?
CVE-2025-71389 affects Cal.com versions before 5.9.9.