Junglewise Threat Intelligence

CVE-2024-58355: Cal.com stored XSS in booking question labels

CVE-2024-58355 · Severity: high · CVSS 8.9 · Published 2026-07-23

Technologies: Cal.Com, Cal.com Cal.diy. Vendors: Cal.com.

Executive brief

Cal.com, an open-source scheduling platform, contains a security flaw in how it handles booking form questions. An attacker with an account can create a malicious booking link that, when viewed by another user, executes unauthorized code in their browser. This could allow an attacker to steal sensitive information, such as session cookies or API keys, from unsuspecting users or administrators.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Cal.com versions up to 4.7.15. The vulnerability is located in the single booking view component, which renders booking-question field labels using React's 'dangerouslySetInnerHTML' attribute without proper sanitization or escaping. An attacker with low privileges (the ability to create an event type) can inject arbitrary HTML or JavaScript into a booking-question label. When a victim navigates to the resulting booking URL, the malicious payload executes in the context of their browser session. This can lead to the theft of sensitive data, including API keys and local storage content. The issue is resolved in version 4.7.16.

Affected products

  • Cal.com cal.diy <= 4.7.15

Timeline

  • 2024-12-03: disclosed: Vulnerability reported by researcher xyzeva
  • 2024-12-04: advisory: GitHub Security Advisory published
  • 2026-07-23: patched: CVE published and fix confirmed in v4.7.16

References

Related threats