| **Affected** | Cal.com (`calcom/cal.diy`) For authorized security testing, CTF, and research only.
Cal.com bundles a version of .js whose **React Server Components (RSC)** request handling **deserializes attacker-controlled input**. A remote, unauthenticated attacker can send a crafted RSC request (a "server action" payload) that causes arbitrary code to run during server-side processing — no auth, no user interaction. It derives from upstream .js **CVE-2025-55182** and is fixed in Cal.com 5.9.9 by updating the dependency.
The server treats the serialized RSC action payload as trusted and materializes/executes it without verifying it corresponds to a registered server action. The fix pins a .js version that validates the action reference before dispatch.
Non-destructive: sends an RSC-style request (` -Action` header) whose serialized action encodes a **benign arithmetic marker**. If the server evaluates it (marker appears in the response), untrusted action payloads are being deserialized/executed → **VULNERABLE**. No OS/process payloads are sent.
python poc.py --target
docker compose up --build # vulnerable on :5003, patched on :5004
- Upgrade Cal.com to **5.9.9+** (pulls the patched .js).
- Only dispatch RSC server actions from a validated registry; never execute action payloads by reference from the request.
- Apply `prevention/` to block unregistered ` -Action` payloads at the edge.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
