CVE-2025-71389 is a critical vulnerability in Cal.com (cal.diy) before version 5.9.9, allowing unauthenticated remote code execution due to a bundled vulnerable version of Next.js. This flaw, derived from CVE-2025-55182, enables attackers to execute arbitrary code via crafted RSC requests without authentication or user interaction. The vulnerability is resolved in version 5.9.9 by updating the affected dependency.
CVE-2026-63768 is a medium-severity open redirect vulnerability in cal.diy through version 6.2.0. The vulnerability exists in the conferencing OAuth callback endpoint and allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. This issue can be exploited for phishing attacks by redirecting visitors from a trusted domain to attacker-controlled URLs.
A medium-severity information disclosure vulnerability exists in calcom cal.diy versions up to 4.9.4. The vulnerability resides in the `getServerSideProps` function within `apps/web/modules/bookings/views/bookings-single-view.getServerSideProps.tsx`, where manipulation of the `cancelledBy` or `rescheduledBy` arguments can lead to unauthorized information disclosure. The attack vector is network-based, req [truncated]
A Server-Side Request Forgery (SSRF) vulnerability exists in the Logo API component of calcom cal.diy versions up to 4.9.4. The vulnerability resides in the `validateUrlForSSRF` function within `apps/web/app/api/logo/route.ts`. An attacker with low privileges can remotely manipulate this function to induce the server to make unauthorized requests to internal or external resources. The CVSS 4.0 vector indi [truncated]
Cross-site request forgery (CSRF) vulnerability in calcom cal.diy up to version 4.9.4. The vulnerability allows remote attackers to perform unauthorized actions via crafted requests. The CVSS 4.0 vector indicates network attack vector with low attack complexity, no privileges required, but user interaction is required. The confidentiality impact is none, integrity impact is low, and availability impact is [truncated]