Back to CVE List

CVE-2026-63768

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
4.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Vulnerability Description

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigned state parameter and onErrorReturnTo field to silently redirect visitors from the trusted domain to attacker-controlled URLs for phishing attacks.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-601
Source
NVD
Vendor
calcom
Product
cal.diy

External References

Discussion (0)

Add Comment

No comments yet. Be the first!