Kestra Kestra OSS: Kestra OSS OS Command Injection Vulnerability
提示 CISA KEV 在册
摘要
Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- Kestra:Kestra OSS
数据来源
- CISA KEV DATABASE
原始链接
- https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjx reference
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk reference
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk reference
- https://nvd.nist.gov/vuln/detail/CVE-2026-49869 reference
时间线
- kev_ingest CISA KEV