A critical remote code execution flaw tracked as CVE-2025-71389 affects the self-hosted Cal.com cal.diy product in versions before 5.9.9, allowing attackers to execute arbitrary code on the server without authentication or user interaction. The bug stems from Cal.com bundling a vulnerable Next.js release affected by the React Server Components deserialization issue CVE-2025-55182, enabling exploitation through a single crafted HTTP request to an RSC endpoint. The vulnerability has been described as severe, with reporting citing a CVSS 10.0 rating and weakness mapping to CWE-94.
The issue was fixed in cal.diy 5.9.9 by updating the affected Next.js dependency. Reporting on the upstream Next.js flaw says it was added to CISA's Known Exploited Vulnerabilities catalog and has seen public proof-of-concept release and real-world abuse by multiple threat actors, including activity linked to cryptominer deployment. Organizations running self-hosted Cal.com instances are being urged to upgrade immediately, limit exposure of RSC endpoints, reduce internet-facing access where possible, and review logs for signs of exploitation attempts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Cal.com fixed CVE-2025-71389 in cal.diy version 5.9.9 by updating the bundled vulnerable Next.js dependency. The flaw affected versions before 5.9.9 and allowed unauthenticated remote code execution via crafted RSC requests.
The upstream Next.js React Server Components deserialization vulnerability, CVE-2025-55182, was added to CISA's Known Exploited Vulnerabilities catalog. The reference says public proof-of-concept code existed and multiple threat actors had exploited it, including for cryptominer delivery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.