Remote Code Execution Vulnerability in Cal.com Exploited

Remote Code Execution Vulnerability in Cal.com Exploited

First seen 8 Sep 2026, 05:01 UTC Sploitus 70.5

Article Content

Browse articles
ThreatCluster

A critical vulnerability affecting Cal.com was identified, allowing remote, unauthenticated attackers to execute arbitrary code via crafted React Server Components (RSC) requests. This issue stems from the deserialization of attacker-controlled input in a bundled version of .js, linked to CVE-2025-55182. The vulnerability can be exploited without any user interaction, making it particularly dangerous. The flaw was patched in Cal.com version 5.9.9, which validates action references before dispatching them. Security researchers have released proof-of-concept (PoC) code demonstrating the exploit. Users are urged to upgrade to the patched version or implement preventive measures against unregistered action payloads. The vulnerability was first disclosed in December 2025 and has been actively exploited since then. The current status indicates that systems running versions prior to 5.9.9 remain vulnerable.

Key Points: • Cal.com is vulnerable to remote code execution due to deserialization flaws in RSC requests. • The vulnerability is linked to CVE-2025-55182 and can be exploited without authentication. • Users must upgrade to Cal.com version 5.9.9 or later to mitigate the risk.

Ask AI about this cluster

Timeline

2025-12-03
CVE-2025-55182 published
A remote code execution vulnerability in Cal.com was disclosed, affecting its RSC request handling.
Sploitus
2025-12-05
CISA KEV addition
CISA added CVE-2025-55182 to its Known Exploited Vulnerabilities catalog due to active exploitation.
Sploitus
2026-01-02
First public PoC released
Security researchers published proof-of-concept code demonstrating the exploit for CVE-2025-55182.
Sploitus
2026-09-08
Patch released
Cal.com released version 5.9.9, which addresses the vulnerability by validating action references.
Sploitus