A critical unauthenticated remote code execution vulnerability (CVE-2025-71389) has been identified in Cal.com (calcom/cal.com), Cal.diy (calcom/cal.diy), and the Next.js framework. The flaw stems from improper handling of React Server Components (RSC) requests, which deserializes attacker-controlled input during server-side processing. This vulnerability is directly linked to the upstream Next.js vulnerability CVE-2025-55182. Attackers can exploit this by sending maliciously crafted RSC payloads to vulnerable servers, enabling arbitrary code execution without requiring authentication or user interaction. The issue affects all versions prior to 5.9.9. Given the CVSS score of 10.0 and critical severity, immediate remediation is strongly advised. Affected systems should be updated to version 5.9.9 or later to eliminate the risk. Organizations utilizing these platforms are urged to prioritize patching and monitor for suspicious activity until mitigations are applied.