CVE-2025-71389
Cal.com versions before 5.9.9 allow attackers to run arbitrary code on the server by sending a specially crafted React Server Components request. The flaw comes from an upstream Next.js issue and requires no authentication or user interaction. Updating to 5.9.9 or later removes the vulnerability.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Cal.com (calcom/cal.diy) users running versions earlier than 5.9.9.
Real-world impact
An attacker can execute any code on the Cal.com server, potentially taking full control, stealing data, or using the server for malicious purposes.
Why this severity
The CVSS score of 10 reflects that the vulnerability is exploitable remotely without authentication, with full control over the system, and no mitigations are available.
What to do about it
- 01Upgrade Cal.com to version 5.9.9 or later.
- 02Restart the Cal.com service after the upgrade.
NVD description
Timeline
- Jul 23, 2026 · 8d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 30, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.