漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Cal.com before 5.9.9 Remote Code Execution via RSC
Vulnerability Description
Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
calcom cal.diy 代码注入漏洞
Vulnerability Description
calcom cal.diy是calcom的Web中间件。 calcom cal.diy 5.9.9之前版本存在代码注入漏洞,该漏洞源于捆绑的Next.js版本中React Server Components (RSC)请求处理反序列化攻击者控制的输入,可能导致未经身份验证的远程攻击者发送特制RSC请求,在服务端处理过程中执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A