Impact
Cal.com (cal.com/diy) before version 5.9.9 is vulnerable to unauthenticated remote code execution through its bundled Next.js React Server Components (RSC) request handling. The flaw allows an attacker to craft an RSC request containing malicious input that is deserialized by the server during processing. This unsanitized deserialization can lead to the execution of arbitrary code on the host without authentication or any required user interaction. The vulnerability derives from an upstream Next.js issue (CVE‑2025‑55182) and is resolved once the affected dependency is updated.
Affected Systems
The affected product is Cal.com DIY, with all releases prior to 5.9.9 impacted. No other vendors or product versions are listed as affected.
Risk and Exploitability
The CVSS score of 10.0 indicates a critical severity, and the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit it by sending a crafted RSC request over the network to the RSC endpoint; no additional authentication is required, and the flaw resides in server‑side deserialization logic. Because the flaw is a direct Remote Code Execution, the impact could be full system compromise if successful. The low EPSS does not reduce the urgency, as the combination of a critical CVSS and exploitation potential via network requests makes this a high‑risk vulnerability that merits swift remediation.
OpenCVE Enrichment