PT-2026-61691 · Cal.Diy · Cal.Diy

·

CVE-2026-63768

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions cal.diy versions 6.2.0 and earlier
Description An open redirect issue exists in the conferencing OAuth callback endpoint. Attackers can redirect users to arbitrary URLs by crafting malicious state parameters, specifically exploiting the unsigned state parameter and the onErrorReturnTo field. This allows visitors to be silently redirected from a trusted domain to attacker-controlled URLs, which can be used for phishing attacks.
Recommendations Update cal.diy to a version later than 6.2.0.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63768

Affected Products

Cal.Diy