Stored Cross-Site Scripting in Kestra's Markdown Parser
CVE-2026-55839
8.7HIGH
What is CVE-2026-55839?
Kestra is an open-source, event-driven orchestration platform that contains a vulnerability in its custom Markdown parser. Before version 1.3.24, the parser allowed users with permission to create or update a Flow description to inject JavaScript event-handler attributes using a custom syntax. This could lead to stored cross-site scripting (XSS), posing a risk when another user accesses the description or information panel in the Flow list. The vulnerability has been addressed in version 1.3.24.
Affected Version(s)
kestra < 1.3.24
