Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

kestra-io — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting kestra-io. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kestra-io is an open-source workflow automation platform designed for orchestrating complex data pipelines and infrastructure tasks. Historically, it has been susceptible to remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, with four CVEs documented to date. The platform's security posture is characterized by its containerized execution environment, which helps contain potential impacts. While no major public security incidents have been reported, the presence of RCE vulnerabilities in past versions highlights the importance of timely updates and proper input validation in workflow definitions.

Found 14 results / 14Clear Filters
Top products by kestra-io: kestra
CVE IDTitleCVSSSeverityPublished
CVE-2026-73247 Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata — kestraCWE-918 8.6 High2026-08-11
CVE-2026-73246 Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials — kestraCWE-200 7.5 High2026-08-11
CVE-2026-73245 Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth — kestraCWE-306 6.5 Medium2026-08-11
CVE-2026-49869 Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter` — kestraCWE-78 10.0 Critical2026-06-26
CVE-2026-45807 Kestra: Path traversal via URL-encoded "%2E%2E" in execution and namespace file endpoints allows arbitrary file read — kestraCWE-22 7.7 High2026-06-26
CVE-2026-49984 Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard) — kestraCWE-22 7.7 High2026-06-26
CVE-2026-53576 Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass — kestraCWE-94 10.0 Critical2026-06-26
CVE-2026-53577 Kestra: Cross-Execution File Read via Preview Endpoint (IDOR) — kestraCWE-863 6.5 Medium2026-06-26
CVE-2026-55069 Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack — kestraCWE-916 8.7 High2026-06-26
CVE-2026-48129 Kestra task inputFiles accepts traversal filenames for worker file writes — kestraCWE-22 6.5 Medium2026-06-19
CVE-2026-34612 Kestra: Remote Code Execution via SQL Injection — kestraCWE-89 10.0 Critical2026-04-03
CVE-2026-33664 Kestra Vulnerable to Stored Cross-Site Scripting via Flow YAML Fields — kestraCWE-79 7.3 High2026-03-26
CVE-2026-29082 Kestra: Stored Cross-Site Scripting in Markdown File Preview — kestraCWE-79 7.3 High2026-03-06
CVE-2025-53543 Kestra allows Stored XSS before 0.22 — kestraCWE-79 4.2 Medium2025-07-07

This page lists every published CVE security advisory associated with kestra-io. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.