PT-2026-28508 · Kestra · Kestra

Dmitrii-Zalmanov

·

Published

2026-03-26

·

Updated

2026-03-26

·

CVE-2026-33664

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kestra versions up to and including 1.3.3
Description Kestra is an open-source, event-driven orchestration platform. Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields – description, inputs[].displayName, inputs[].description – through the Markdown.vue component instantiated with html: true. The resulting HTML is injected into the DOM via Vue's v-html without any sanitization. This allows a flow author to embed arbitrary JavaScript that executes in the browser of any user who views or interacts with the flow. This issue affects different components and data sources, requiring minimal user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33664
GHSA-V2MC-8Q95-G7HP

Affected Products

Kestra