kestra是Kestra公司开源的一个工作流自动化平台。 kestra-io Kestra 1.0.45之前版本和1.1.0版本至1.3.21之前版本存在输入验证错误漏洞,该漏洞源于AuthenticationFilter使用后缀匹配而非精确路径匹配来白名单配置端点,导致任何以"/configs"结尾的API路径绕过身份验证,可能导致未经身份验证的远程攻击者创建和执行任意工作流,进而实现远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-53576 | 10.0 CRITICAL | Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass |
| CVE-2026-55069 | 8.7 HIGH | Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack |
| CVE-2026-45807 | 7.7 HIGH | Kestra: Path traversal via URL-encoded "%2E%2E" in execution and namespace file endpoints |
| CVE-2026-49984 | 7.7 HIGH | Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary s |
| CVE-2026-53577 | 6.5 MEDIUM | Kestra: Cross-Execution File Read via Preview Endpoint (IDOR) |
No comments yet