Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

kestra — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in kestra, with AI-generated Chinese analysis, references, and POCs.

This page aggregates publicly reported security vulnerabilities affecting Kestra, the open-source workflow orchestration platform developed by Kestra Inc. The collection covers a broad range of defect classes, including remote code execution, privilege escalation, and deserialization flaws, spanning advisories published from 2021 through the current year. Readers can use this index to track the vendor's advisory history, analyze recurring weakness patterns within a single product, or cross-reference specific vulnerability records by date and severity. The interface groups entries by CWE type and publication timestamp, enabling efficient filtering for trend analysis and risk assessment without requiring individual CVE lookups. This structured overview supports security teams in evaluating the long-term resilience of the Kestra ecosystem and identifying systemic weaknesses that persist across multiple releases.

Vendor: kestra-io

CVE ID Title CVSS Severity Published
CVE-2026-55839 Kestra: Stored XSS via custom Markdown [[link]] attribute injection CWE-79 8.7 High 2026-08-18
CVE-2026-73247 Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata CWE-918 8.6 High 2026-08-11
CVE-2026-73246 Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials CWE-200 7.5 High 2026-08-11
CVE-2026-73245 Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth CWE-306 6.5 Medium 2026-08-11
CVE-2026-49869 Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter` CWE-78 10.0 Critical 2026-06-26
CVE-2026-45807 Kestra: Path traversal via URL-encoded "%2E%2E" in execution and namespace file endpoints allows arbitrary file read CWE-22 7.7 High 2026-06-26
CVE-2026-49984 Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard) CWE-22 7.7 High 2026-06-26
CVE-2026-53576 Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass CWE-94 10.0 Critical 2026-06-26
CVE-2026-53577 Kestra: Cross-Execution File Read via Preview Endpoint (IDOR) CWE-863 6.5 Medium 2026-06-26
CVE-2026-55069 Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack CWE-916 8.7 High 2026-06-26
CVE-2026-48129 Kestra task inputFiles accepts traversal filenames for worker file writes CWE-22 6.5 Medium 2026-06-19
CVE-2026-34612 Kestra: Remote Code Execution via SQL Injection CWE-89 10.0 Critical 2026-04-03
CVE-2026-33664 Kestra Vulnerable to Stored Cross-Site Scripting via Flow YAML Fields CWE-79 7.3 High 2026-03-26
CVE-2026-29082 Kestra: Stored Cross-Site Scripting in Markdown File Preview CWE-79 7.3 High 2026-03-06
CVE-2025-53543 Kestra allows Stored XSS before 0.22 CWE-79 4.2 Medium 2025-07-07

All 15 known CVE vulnerabilities affecting kestra with full Chinese analysis, references, and POCs where available.