What is CVE-2025-71389?
This CVE describes an unauthenticated remote code execution (RCE) vulnerability in Cal.com (calcom/cal.diy) versions before 5.9.9, caused by the bundled Next.js's insecure deserialization of attacker-controlled input in React Server Components (RSC) request handling. Users must immediately upgrade to version 5.9.9 or later to mitigate the risk.
Azərbaycanca: Bu CVE, Cal.com platformasının 5.9.9-dan əvvəlki versiyalarında autentifikasiya olmadan uzaqdan kod icrası (RCE) zəifliyini təsvir edir. Zəiflik, Next.js-in React Server Components (RSC) sorğu emalı zamanı hücumçunun idarə etdiyi verilənləri təhlükəsiz şəkildə işləməməsindən qaynaqlanır. Cal.com istifadəçiləri dərhal 5.9.9 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which versions of the Cal.com platform are vulnerable to CVE-2025-71389?
All versions of the Cal.com platform before 5.9.9 are vulnerable to CVE-2025-71389.
What action is required to mitigate the CVE-2025-71389 vulnerability?
To mitigate this vulnerability, the Cal.com platform must be immediately upgraded to version 5.9.9 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.