Executive brief
Cal.com (cal.diy) is an open-source scheduling platform used to manage appointments and bookings. A privacy flaw allows unauthenticated users to see the private email addresses of event organizers, even when the 'hideOrganizerEmail' privacy setting is enabled. This occurs when an organizer cancels or reschedules a meeting, potentially exposing them to phishing or unwanted contact.
Technical details
An information exposure vulnerability exists in Cal.com (cal.diy) versions up to 4.9.4 within the 'getServerSideProps' function of the bookings module. The application fails to sanitize the 'cancelledBy' and 'rescheduledBy' properties in the bookingInfo JSON payload before it is serialized into the Server-Side Rendered (SSR) public page and TRPC API responses. An unauthenticated attacker with access to a public booking UID can retrieve the raw email address of the organizer if the organizer has performed a cancellation or rescheduling action. This bypasses the 'hideOrganizerEmail' security control intended to mask the organizer's identity. As of the advisory date, the vendor has not responded to the disclosure.
Affected products
- Cal.com cal.diy up to 4.9.4
Timeline
- 2026-04-06: disclosed: Vulnerability details and PoC shared via GitHub Gist
- 2026-05-24: advisory: CVE-2026-9349 published via VulDB/NVD