Sceawere

Vulnerability Detail

CVE-2026-57858UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Cal.com Stored Cross-Site Scripting

Vulnerability Metadata

Severity
High
Score / CVSS
8.9
Creation Date
3h ago
Vendor
Cal.com
Product
Cal.com Self-Hosted (Cal.diy)
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization. Attackers can close the inline script string literal with a crafted payload that executes in the browser of every visitor to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF-able endpoints to persist payloads on additional events.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.9",
  "pubDate": "2026-08-12T13:17:22.943Z",
  "pubdate": "2026-08-12T13:17:22.943Z",
  "executiveSummary": "A stored cross-site scripting vulnerability exists within the BookingPageTagManager component of Cal.com Cal.diy versions 2.1.1 through 6.2.0.\nThe vulnerability allows authenticated event owners to supply malicious analytics tracking IDs lacking proper input sanitization.\nWhen a victim visits the affected public booking page, the injected payload executes in their browser context.\nSuccessful exploitation enables session cookie theft, the forging of authenticated requests, and wormable propagation by chaining the attack with cross-site request forgery-able endpoints to persist malicious payloads across additional events.\nThe primary risk stems from compromised user sessions and unauthorized actions executed on behalf of booking page visitors.\nAttackers require authenticated access as an event owner to supply the malicious tracking ID input.",
  "technicalDetails": "The vulnerability resides in the BookingPageTagManager component of Cal.com Cal.diy versions 2.1.1 through 6.2.0, which processes analytics tracking IDs without implementing adequate input sanitization or output encoding.\nThe root cause is the unsafe injection of user-supplied tracking ID values directly into an inline script string literal within the rendered Document Object Model of public booking pages.\nAn authenticated attacker with event owner privileges initiates the attack flow by supplying a specially crafted payload designed to prematurely close the inline script string literal.\nOnce the payload is stored within the backend database, it is served to any unauthenticated or authenticated visitor accessing the affected public booking page.\nWhen the visitor's browser parses the HTML and executes the embedded script, the malicious JavaScript runs within the origin context of the booking page.\nPost-exploitation impact includes the potential theft of session cookies, the execution of forged authenticated requests leveraging the victim's session, and wormable propagation.\nWormable propagation is achieved by chaining the cross-site scripting payload with cross-site request forgery-vulnerable endpoints, allowing the attacker to automatically create or modify additional events and persist the payload across the application."
}
CVE-2026-57858: Cal.com Stored Cross-Site Scripting (HIGH Severity, CVSS: 8.9) - Sceawere