Vulnerabilities in kestra-io

15 results
Vexday analysis

Kestra-io apresenta 11 vulnerabilidades catalogadas, sendo 3 críticas e 7 publicadas nos últimos 90 dias, indicando ritmo acelerado de descobertas recentes. A fraqueza dominante é CWE-22 (path traversal), que permite manipulação de caminhos de arquivo. Nenhuma vulnerabilidade está sob exploração ativa conforme KEV, reduzindo risco imediato, porém a recência das divulgações demanda monitoramento contínuo de patches.

CVE-2026-53576CRITICALKestra: Unauthenticated RCE via /configs path-suffix auth-filter bypassEPSS 2.2%CVE-2026-49869CRITICALKestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`EPSS 0.9%CVE-2026-34612CRITICALKestra: Remote Code Execution via SQL InjectionEPSS 0.7%CVE-2026-45807HIGHKestra: Path traversal via URL-encoded "%2E%2E" in execution and namespace file endpoints allows arbitrary file readEPSS 0.5%CVE-2026-49984HIGHKestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard)EPSS 0.5%CVE-2026-48129MEDIUMKestra task inputFiles accepts traversal filenames for worker file writesEPSS 0.4%CVE-2026-73246HIGHKestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentialsEPSS 0.3%CVE-2026-53577MEDIUMKestra: Cross-Execution File Read via Preview Endpoint (IDOR)EPSS 0.3%CVE-2026-73247HIGHKestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadataEPSS 0.3%CVE-2026-33664HIGHKestra Vulnerable to Stored Cross-Site Scripting via Flow YAML FieldsEPSS 0.3%CVE-2026-29082HIGHKestra: Stored Cross-Site Scripting in Markdown File PreviewEPSS 0.2%CVE-2026-55069HIGHKestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force AttackEPSS 0.2%CVE-2026-73245MEDIUMKestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-authEPSS 0.2%CVE-2025-53543MEDIUMKestra allows Stored XSS before 0.22EPSS 0.2%CVE-2026-55839HIGHKestra: Stored XSS via custom Markdown [[link]] attribute injectionEPSS