Kestra 是一个开源的、事件驱动的编排平台。在 1.3.24 版本之前,Kestra 的自定义 Markdown 解析器(位于 )允许拥有创建或更新流程(Flow)描述权限的用户,通过自定义的 语法注入 JavaScript 事件处理器属性,从而导致存储型跨站脚本(Stored XSS)漏洞。当其他用户查看该流程列表中的描述或信息面板时,恶意脚本将被执行。该问题已在 1.3.24 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: stored XSS confirmed — injected onmouseover handler executed in the victim page context and exfiltrated secret PROOF_b206e25fd33150a4
No comments yet