CVE-2026-29082 Details
Description
Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview renders user-supplied Markdown (.md) with markdown-it instantiated as html:true and injects the resulting HTML with Vue’s v-html without sanitisation. At time of publication, there are no publicly available patches.
A stored cross-site scripting vulnerability has been identified in Kestra, an event-driven orchestration platform, in versions through 1.1.10. The issue arises because the execution-file preview feature renders user-supplied Markdown files with 'markdown-it' configured to allow HTML. This unfiltered HTML is then injected into the application using Vue's 'v-html' directive, creating an opportunity for malicious scripts to be executed. At the time of publication, no patches are available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kestra-io/kestra/security/advisories/GHSA-r36c-83hm-pc8j | CISA-ADP | ExploitVendor Advisory |
| https://github.com/kestra-io/kestra/releases/tag/v1.0.30 | [email protected] | ProductRelease Notes |
| https://github.com/kestra-io/kestra/security/advisories/GHSA-r36c-83hm-pc8j | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kestra kestra | <= 1.1.10 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 10, 2026 | Initial Analysis | [email protected] |
| Mar 9, 2026 | CVE Modified | CISA-ADP |
| Mar 6, 2026 | New CVE Received | [email protected] |