Executive brief
Cal.com is an open-source scheduling platform used by businesses to manage appointments and meetings. A critical security flaw allows an unauthenticated attacker to remotely execute malicious code on the server hosting the application. This could lead to a complete system takeover, theft of sensitive customer data, or disruption of scheduling services.
Technical details
Cal.com (cal.diy) versions prior to 5.9.9 are vulnerable to remote code execution (RCE) due to an upstream vulnerability in Next.js (CVE-2025-55182). The flaw exists in the React Server Components (RSC) request handling, where the server deserializes attacker-controlled input from the React flight protocol. A remote, unauthenticated attacker can send a specially crafted RSC request to trigger the execution of arbitrary code during server-side processing. The vulnerability is rooted in the 'react-server-dom-webpack' (and related) packages used by Next.js App Router. The issue is resolved in Cal.com 5.9.9 by updating the Next.js dependency to a patched version (e.g., 15.5.7 or 15.4.8).
Affected products
- Cal.com cal.diy < 5.9.9
Timeline
- 2025-12-03: advisory: Upstream Next.js vulnerability disclosed (GHSA-9qr9-h5gf-34mp)
- 2025-12-04: patched: Cal.com merged PR to bump Next.js version
- 2025-12-07: advisory: Cal.com published security advisory GHSA-qjx2-5xqp-cpf4
- 2026-07-23: disclosed: CVE-2025-71389 published to NVD