PatchSiren

calcom CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL calcom CVE published 2026-07-23

CVE-2025-71389

CVE-2025-71389 is a critical vulnerability in Cal.com (cal.diy) before version 5.9.9, allowing unauthenticated remote code execution due to a bundled vulnerable version of Next.js. This flaw, derived from CVE-2025-55182, enables attackers to execute arbitrary code via crafted RSC requests without authentication or user interaction. The vulnerability is resolved in version 5.9.9 by updating the affected dependency.

MEDIUM calcom CVE published 2026-07-20

CVE-2026-63768

CVE-2026-63768 is a medium-severity open redirect vulnerability in cal.diy through version 6.2.0. The vulnerability exists in the conferencing OAuth callback endpoint and allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. This issue can be exploited for phishing attacks by redirecting visitors from a trusted domain to attacker-controlled URLs.

MEDIUM calcom CVE published 2026-05-24

CVE-2026-9349

A medium-severity information disclosure vulnerability exists in calcom cal.diy versions up to 4.9.4. The vulnerability resides in the `getServerSideProps` function within `apps/web/modules/bookings/views/bookings-single-view.getServerSideProps.tsx`, where manipulation of the `cancelledBy` or `rescheduledBy` arguments can lead to unauthorized information disclosure. The attack vector is network-based, req [truncated]

LOW calcom CVE published 2026-05-23

CVE-2026-9304

A Server-Side Request Forgery (SSRF) vulnerability exists in the Logo API component of calcom cal.diy versions up to 4.9.4. The vulnerability resides in the `validateUrlForSSRF` function within `apps/web/app/api/logo/route.ts`. An attacker with low privileges can remotely manipulate this function to induce the server to make unauthorized requests to internal or external resources. The CVSS 4.0 vector indi [truncated]

LOW calcom CVE published 2026-05-23

CVE-2026-9303

Cross-site request forgery (CSRF) vulnerability in calcom cal.diy up to version 4.9.4. The vulnerability allows remote attackers to perform unauthorized actions via crafted requests. The CVSS 4.0 vector indicates network attack vector with low attack complexity, no privileges required, but user interaction is required. The confidentiality impact is none, integrity impact is low, and availability impact is [truncated]