CVE-2026-29082

Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview renders user-supplied Markdown (.md) with markdown-it instantiated as html:true and injects the resulting HTML with Vue’s v-html without sanitisation. At time of publication, there are no publicly available patches.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-06 17:16

Updated : 2026-06-17 10:29


NVD link : CVE-2026-29082

Mitre link : CVE-2026-29082

CVE.ORG link : CVE-2026-29082


JSON object : View

Products Affected

kestra

  • kestra
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')