PT-2026-64180 · Cal.Com · Cal.Com

·

CVE-2024-58354

·

Published

2026-07-23

·

Updated

2026-07-24

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions cal.com (main branch)
Description A repository takeover issue exists in the GitHub Actions workflows. The pr.yml workflow utilizes the pull request target trigger with default write permissions, which are passed to check-types.yml. This second workflow performs a checkout of code from a pull request using the dangerous-git-checkout action and executes it via yarn install and package.json scripts. An attacker can submit a pull request containing arbitrary commands that execute with the repository's write-scoped GITHUB TOKEN, enabling them to push commits, merge or mutate pull requests, manage comments, and delete or force-push branches.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58354
GHSA-P3F6-52GV-CJ7M

Affected Products

Cal.Com