Remote Code Execution Vulnerability in Kestra Event-Driven Orchestration Platform
CVE-2026-29082

7.3HIGH

Key Information:

Vendor

Kestra-io

Status
Vendor
CVE Published:
6 March 2026

What is CVE-2026-29082?

The Kestra platform's execution-file preview feature is vulnerable due to improper handling of user-supplied Markdown (.md) files. In versions 1.1.10 and earlier, this feature uses the 'markdown-it' library to render Markdown into HTML, with the rendered HTML being injected into the application using Vue's 'v-html' directive without proper sanitization. This flaw could potentially allow an attacker to execute arbitrary HTML or JavaScript code, leading to security risks including remote code execution. At the time of this report, there are no publicly available patches to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

kestra <= 1.1.10

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.