CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2024-58354

criticalCVSS 9.9covered by 1 sourcefirst seen 2026-07-23
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to check-types.yml. check-types.yml then performs a 'dangerous' checkout of the attacker-submitted pull request code (via the dangerous-git-checkout action) and subsequently executes it (through yarn install and package.json scripts). An attacker can open a pull request whose code runs arbitrary commands with the repository's write-scoped GITHUB_TOKEN, allowing them to push commits, merge or mutate pull requests, add or delete comments, and delete or force-push branches, thereby compromising the repository. The main branch is affected; no patched version is available.

⚡ Watch CVE-2024-58354

Get an email if CVE-2024-58354 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2024-58354

CVE.org record

Embed the live status

CVE-2024-58354 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2024-58354 status](https://www.csirts.com/badge/CVE-2024-58354)](https://www.csirts.com/cve/CVE-2024-58354)