{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cal.diy/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.9,"id":"CVE-2026-57858"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cal.diy"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Cal.com"],"content_html":"\u003cp\u003eCal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting (XSS) vulnerability in the BookingPageTagManager component. The vulnerability arises due to a lack of sanitization for analytics tracking IDs provided by event owners. An attacker with authenticated access to an event account can supply a crafted tracking ID containing JavaScript payloads. When a user visits the public-facing booking page associated with that event, the malicious script executes within the visitor's browser session.\u003c/p\u003e\n\u003cp\u003eThis flaw poses a significant risk to organizations using Cal.diy for scheduling, as it allows for the theft of session cookies, the execution of unauthorized actions on behalf of the visitor, and potential wormable propagation. By chaining this XSS with cross-site request forgery (CSRF) vulnerabilities, an attacker could force persistent payload injection across multiple booking pages, escalating the impact of the compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker authenticates to their own Cal.diy account.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to the event configuration or analytics settings menu.\u003c/li\u003e\n\u003cli\u003eThe attacker locates the analytics tracking ID input field within the BookingPageTagManager settings.\u003c/li\u003e\n\u003cli\u003eThe attacker submits a malicious tracking ID containing a JavaScript payload designed to break out of the script tag context.\u003c/li\u003e\n\u003cli\u003eThe server fails to sanitize the input and saves the payload to the application database.\u003c/li\u003e\n\u003cli\u003eA legitimate victim visits the attacker-controlled public booking page.\u003c/li\u003e\n\u003cli\u003eThe application renders the injected script in the victim's browser.\u003c/li\u003e\n\u003cli\u003eThe script executes, resulting in session hijacking or subsequent unauthorized requests.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the complete compromise of visitor browser sessions. Observed impacts include session hijacking, the ability to make authenticated requests as the visitor, and the potential for self-propagating payloads that affect other users of the booking platform. Given the public nature of these pages, any site visitor is a potential target.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update Cal.diy to the latest version, which includes sanitization logic for the analytics tracking ID.\u003c/li\u003e\n\u003cli\u003eAudit event analytics configuration settings for any unexpected or suspicious script tags or obfuscated tracking identifiers.\u003c/li\u003e\n\u003cli\u003eReview logs for non-standard characters in analytics configuration API calls.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-12T14:46:43Z","date_published":"2026-08-12T14:46:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cal-diy-xss/","summary":"Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored XSS vulnerability allowing authenticated event owners to inject malicious JavaScript into public booking pages.","title":"Stored XSS in Cal.com Cal.diy via BookingPageTagManager","url":"https://feed.craftedsignal.io/briefs/2026-08-cal-diy-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cal.diy","version":"https://jsonfeed.org/version/1.1"}