CVE-2026-9304: Server-Side Request Forgery in calcom cal.diy
A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/api/logo/route.ts of the component Logo API. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Technical Summary
This vulnerability involves a server-side request forgery in the validateUrlForSSRF function of the file apps/web/app/api/logo/route.ts in calcom cal.diy versions 4.9.0 through 4.9.4. An attacker can remotely manipulate this function to cause the server to make unintended requests. The exploitability is rated as difficult, and the CVSS 4.0 vector indicates a network attack vector with high attack complexity and low privileges required. No official remediation or patch has been published by the vendor.
Potential Impact
Successful exploitation could allow an attacker to induce the server to perform unauthorized requests to internal or external systems, potentially leading to information disclosure or interaction with internal services. However, the low CVSS score and high attack complexity reduce the likelihood and impact of exploitation. No known active exploitation in the wild has been reported.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Users should monitor vendor communications for updates. Given the complexity of exploitation and low severity, immediate urgent action is not mandated, but cautious use of affected versions is advised. Network-level controls to restrict outbound requests from the affected service may reduce risk.
CVE-2026-9304: Server-Side Request Forgery in calcom cal.diy
Description
A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSSRF of the file apps/web/app/api/logo/route.ts of the component Logo API. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS v4.0
Score 2.3low
Affected software
pkg:npm/calcom/cal.diyRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves a server-side request forgery in the validateUrlForSSRF function of the file apps/web/app/api/logo/route.ts in calcom cal.diy versions 4.9.0 through 4.9.4. An attacker can remotely manipulate this function to cause the server to make unintended requests. The exploitability is rated as difficult, and the CVSS 4.0 vector indicates a network attack vector with high attack complexity and low privileges required. No official remediation or patch has been published by the vendor.
Potential Impact
Successful exploitation could allow an attacker to induce the server to perform unauthorized requests to internal or external systems, potentially leading to information disclosure or interaction with internal services. However, the low CVSS score and high attack complexity reduce the likelihood and impact of exploitation. No known active exploitation in the wild has been reported.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor. Users should monitor vendor communications for updates. Given the complexity of exploitation and low severity, immediate urgent action is not mandated, but cautious use of affected versions is advised. Network-level controls to restrict outbound requests from the affected service may reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-05-22T17:54:42.546Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a11b6c509f6977edb26300f
Added to database: 05/23/2026, 14:16:37 UTC
Last enriched: 05/30/2026, 20:39:05 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 125
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.