Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerability
Info Listed in CISA KEV
Summary
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Kestra:Kestra OSS
Sources
- CISA KEV DATABASE
Original Links
- https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx reference
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk reference
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk reference
- https://nvd.nist.gov/vuln/detail/CVE-2026-49869 reference
Timeline
- kev_ingest CISA KEV