← Back to browse · API

CVE-2025-71389

Severity
CRITICAL
CVSS
10.0
EPSS
0.00928
Risk score
40.32
CISA KEV
No
PoC
Yes
Published
2026-07-23
Modified
2026-07-28
First seen
2026-08-05
Aliases
EUVD-2025-210506, GHSA-8449-9VW6-7MP5
Products
calcom:cal.diy 0 <5.9.9
Sources
nvd CVE-2025-71389
github c5b4c2730ab6f8045706391c|CVE-2025-71389
euvd EUVD-2025-210506
packetstorm 99fad1b21932750194bc833e|CVE-2025-71389

Description

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.

References