Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored XSS due to improper handling of HTTP response received. This vulnerability is fixed in 0.22.0.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Jul 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 07 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored XSS due to improper handling of HTTP response received. This vulnerability is fixed in 0.22.0. | |
Title | Kestra allows Stored XSS before 0.22 | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-07T19:54:46.526Z
Updated: 2025-07-07T20:54:44.844Z
Reserved: 2025-07-02T15:15:11.515Z
Link: CVE-2025-53543

Updated: 2025-07-07T20:54:39.898Z

Status : Received
Published: 2025-07-07T20:15:28.323
Modified: 2025-07-07T20:15:28.323
Link: CVE-2025-53543

No data.