{"id":"CVE-2025-71389","title":"Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input","summary":"Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote at…","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-94"],"published":"2026-07-23","updated":"2026-09-29","sourceUpdated":"2026-09-29T14:10:00.117","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-71389","references":[{"url":"https://github.com/advisories/GHSA-9qr9-h5gf-34mp","label":"disclosure@vulncheck.com"},{"url":"https://github.com/calcom/cal.diy/pull/25592","label":"disclosure@vulncheck.com"},{"url":"https://github.com/calcom/cal.diy/security/advisories/GHSA-qjx2-5xqp-cpf4","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/cal-com-before-remote-code-execution-via-rsc","label":"disclosure@vulncheck.com"}],"tags":["nvd","exploit-available"],"epss":0.01354,"epssPercentile":0.70497,"exploits":{"github":1,"githubRepos":["https://github.com/0xdak/CVE-2025-71389_exploit"],"checkedAt":"2026-09-29T14:36:48.263Z"},"exploitAvailable":true,"ingestedAt":"2026-09-29T14:36:14.069Z","slug":"CVE-2025-71389","body":"## Overview\n\nCal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":67,"depthScoreParts":{"impact":55,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[]}