Sploitus
Remote Code Execution Vulnerability in Cal.com Exploited
Article Content
A critical vulnerability affecting Cal.com was identified, allowing remote, unauthenticated attackers to execute arbitrary code via crafted React Server Components (RSC) requests. This issue stems from the deserialization of attacker-controlled input in a bundled version of .js, linked to CVE-2025-55182. The vulnerability can be exploited without any user interaction, making it particularly dangerous. The flaw was patched in Cal.com version 5.9.9, which validates action references before dispatching them. Security researchers have released proof-of-concept (PoC) code demonstrating the exploit. Users are urged to upgrade to the patched version or implement preventive measures against unregistered action payloads. The vulnerability was first disclosed in December 2025 and has been actively exploited since then. The current status indicates that systems running versions prior to 5.9.9 remain vulnerable.
Key Points: • Cal.com is vulnerable to remote code execution due to deserialization flaws in RSC requests. • The vulnerability is linked to CVE-2025-55182 and can be exploited without authentication. • Users must upgrade to Cal.com version 5.9.9 or later to mitigate the risk.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.