Executive brief
cal.diy is an open-source scheduling platform. A security flaw in its conferencing integration allows attackers to create malicious links that appear to come from a trusted domain but instead redirect users to a fraudulent website. This could be used in phishing campaigns to steal user credentials or distribute malware by exploiting the user's trust in the scheduling service.
Technical details
An open redirect vulnerability (CWE-601) exists in the conferencing OAuth callback endpoint of cal.diy. The vulnerable component, located in the conferencing controller, fails to validate the 'state' query parameter and its 'onErrorReturnTo' field. An attacker can craft a URL containing a malicious JSON-encoded state parameter; when the endpoint encounters an error (which can be trivially triggered by providing an 'error' parameter), it issues a 301 redirect to the attacker-supplied URL. This occurs because the endpoint is unauthenticated and lacks signature or integrity checks on the state object. A patch has been proposed to implement origin validation using a new utility function.
Affected products
- calcom cal.diy <= 6.2.0
Timeline
- 2026-05-18: disclosed: Private disclosure to vendor
- 2026-06-30: other: Public issue and pull request created on GitHub
- 2026-07-20: advisory: CVE published and NVD record created