PT-2026-28508 · Kestra · Kestra

Dmitrii-Zalmanov

·

Publicado

2026-03-26

·

Atualizado

2026-03-26

·

CVE-2026-33664

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kestra versions up to and including 1.3.3
Description Kestra is an open-source, event-driven orchestration platform. Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields – description, inputs[].displayName, inputs[].description – through the Markdown.vue component instantiated with html: true. The resulting HTML is injected into the DOM via Vue's v-html without any sanitization. This allows a flow author to embed arbitrary JavaScript that executes in the browser of any user who views or interacts with the flow. This issue affects different components and data sources, requiring minimal user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33664
GHSA-V2MC-8Q95-G7HP

Produtos afetados

Kestra