← Back to Research Blog
CRITICAL CVE-2025-71389

Critical RCE Vulnerability Unveiled in Cal.com: Immediate Remediation Required for Enterprise Deployments

10.0
CRITICAL
cal.com, cal.diy, next.js
2026-08-13

Overview

CVE-2025-71389 represents a CVSS 10.0 unauthenticated remote code execution vulnerability in Cal.com's self-hosted cal.diy variant. Exploitation requires no credentials or user interaction, enabling attackers to execute arbitrary code by exploiting insecure deserialization in a vulnerable Next.js dependency.


Technical Analysis

The vulnerability stems from Cal.com versions <5.9.9 bundling a Next.js version affected by CVE-2025-55182. React Server Components (RSC) request parsing deserializes attacker-controlled data without validation, enabling code execution during server-side processing. An attacker need only craft a malicious RSC HTTP request to any exposed Cal.com endpoint to achieve persistence-free exploitation.

Enterprise & DIB Impact

Defense Industrial Base and enterprise environments leveraging Cal.com for scheduling or booking systems face catastrophic risk, as attackers could exfiltrate sensitive data, disrupt operations, or lateral pivot using compromised hosts. The zero-credential requirement amplifies exposure for misconfigured or internet-accessible deployments.

Recommended Actions

Need Help Assessing Your Exposure?

Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.

Schedule a Consultation
Full security advisory on 247alerts.net →
Axiom Cyber Research
Axiom Cyber Research, LLC is a Service-Disabled Veteran-Owned Small Business (SDVOSB) providing elite cybersecurity consulting to the Defense Industrial Base and regulated sectors. Founded by a 20+ year veteran with deep offensive and defensive cyber expertise. Our CVE intelligence program actively tracks emerging vulnerabilities to help organizations prioritize remediation and reduce exposure windows.
Baltimore, MD  ·  axiomcyber.io  ·  247alerts.net  ·  SDVOSB  ·  NAICS 541512