Critical RCE Vulnerability Unveiled in Cal.com: Immediate Remediation Required for Enterprise Deployments
Overview
CVE-2025-71389 represents a CVSS 10.0 unauthenticated remote code execution vulnerability in Cal.com's self-hosted cal.diy variant. Exploitation requires no credentials or user interaction, enabling attackers to execute arbitrary code by exploiting insecure deserialization in a vulnerable Next.js dependency.
Technical Analysis
The vulnerability stems from Cal.com versions <5.9.9 bundling a Next.js version affected by CVE-2025-55182. React Server Components (RSC) request parsing deserializes attacker-controlled data without validation, enabling code execution during server-side processing. An attacker need only craft a malicious RSC HTTP request to any exposed Cal.com endpoint to achieve persistence-free exploitation.
Enterprise & DIB Impact
Defense Industrial Base and enterprise environments leveraging Cal.com for scheduling or booking systems face catastrophic risk, as attackers could exfiltrate sensitive data, disrupt operations, or lateral pivot using compromised hosts. The zero-credential requirement amplifies exposure for misconfigured or internet-accessible deployments.
Recommended Actions
- Upgrade cal.diy to version 5.9.9 immediately
- restrict Cal.com endpoints to trusted internal networks using zero-trust architecture
- implement WAF rules to detect anomalous RSC request patterns
- conduct dependency audits for other vulnerable Next.js integrations
- and enable comprehensive server-side logging for post-exploitation forensics.
Need Help Assessing Your Exposure?
Axiom Cyber Research provides vulnerability assessment, red team operations, and security advisory services to the Defense Industrial Base and regulated sectors.
Schedule a ConsultationFull security advisory on 247alerts.net →