A critical unauthenticated remote code execution vulnerability (CVE-2025-71389) has been identified in Cal.com (calcom/cal.com), Cal.diy (calcom/cal.diy), and the Next.js framework. The flaw stems from improper handling of React Server Components (RSC) requests, which deserializes attacker-controlled input during server-side processing. This vulnerability is directly linked to the upstream Next.js vulnerability CVE-2025-55182. Attackers can exploit this by sending maliciously crafted RSC payloads to vulnerable servers, enabling arbitrary code execution without requiring authentication or user interaction. The issue affects all versions prior to 5.9.9. Given the CVSS score of 10.0 and critical severity, immediate remediation is strongly advised. Affected systems should be updated to version 5.9.9 or later to eliminate the risk. Organizations utilizing these platforms are urged to prioritize patching and monitor for suspicious activity until mitigations are applied.
CRITICAL
CVSS 10.0
CVE-2025-71389
2026-08-13
Critical Remote Code Execution Vulnerability in Cal.com and Next.js Platforms (CVE-2025-71389)
A critical remote code execution vulnerability (CVE-2025-71389) affects Cal.com, Cal.diy, and Next.js platforms. Unauthenticated attackers can exploit this flaw to execute arbitrary code via crafted RSC requests. Immediate patching to version 5.9.9 or later is required to mitigate the risk.