Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3529 articles · 209755 vulns · 37/41 feeds (7d)
← Back to list
8.7
CVE-2026-55839PATCHED
kestra-io · kestra

Kestra: Stored XSS via custom Markdown [[link]] attribute injection

Description

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaScript event-handler attributes through the custom [[link]] syntax, causing stored cross-site scripting when another user opens the description or information panel in the Flow list. This issue is fixed in version 1.3.24.

Affected Products

VendorProductVersions
kestra-iokestra< 1.3.24

References

  • https://github.com/kestra-io/kestra/security/advisories/GHSA-34pm-923j-7wf8(x_refsource_CONFIRM)
  • https://github.com/kestra-io/kestra/pull/16835(x_refsource_MISC)
  • https://github.com/kestra-io/kestra/commit/6c8e6d099ed172cbb6b003b7fb30b7bb1f8f710e(x_refsource_MISC)
  • https://github.com/kestra-io/kestra/releases/tag/v1.3.24(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB17d ago
CVE-2026-55839 | Kestra up to 1.3.23 Markdown parser link.ts cross site scripting
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.7 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
io.kestra:kestra@1.3.24
CWECWE-79
PublishedAug 18, 2026
Trending Score4
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-49869EXPKEV
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
Trending: 138
HIGHCVE-2026-73246
Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials
Trending: 4
HIGHCVE-2026-73247
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
Trending: 4
MEDIUMCVE-2026-73245
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
Trending: 3
HIGHCVE-2026-49984
Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard)

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 18, 2026
Discovered by ZDM
Aug 18, 2026
Patch Available
Aug 18, 2026