## https://sploitus.com/exploit?id=8ADC57BF-D2D7-5DC7-AEF7-75005077DEB5
# CVE-2025-71389 โ Cal.com Unauthenticated RCE (react2shell)
Unauthenticated remote code execution in [Cal.com](https://github.com/calcom/cal.com)
`= 5.9.9` (any patched Next.js: 15.0.5 / 15.1.9 / 15.2.6 / 15.3.6 /
15.4.8 / 15.5.7 / 16.0.7). Do not expose the RSC server-function handler to untrusted
clients, and don't run the app container as root.
## Disclaimer
For authorized security testing and education only. Use it only against systems you own
or have explicit permission to test.