PT-2026-64180 · Cal.Com · Cal.Com
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cal.com (main branch)
Description
A repository takeover issue exists in the GitHub Actions workflows. The
pr.yml workflow utilizes the pull request target trigger with default write permissions, which are passed to check-types.yml. This second workflow performs a checkout of code from a pull request using the dangerous-git-checkout action and executes it via yarn install and package.json scripts. An attacker can submit a pull request containing arbitrary commands that execute with the repository's write-scoped GITHUB TOKEN, enabling them to push commits, merge or mutate pull requests, manage comments, and delete or force-push branches.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cal.Com