Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. As a result, attackers can inject arbitrary SQL expressions into the database query.
References
| Link | Resource |
|---|---|
| https://github.com/kestra-io/kestra/security/advisories/GHSA-365w-2m69-mp9x | Exploit Mitigation Vendor Advisory |
| https://www.link.com | Not Applicable |
| https://github.com/kestra-io/kestra/security/advisories/GHSA-365w-2m69-mp9x | Exploit Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-05-05 19:16
Updated : 2026-07-24 21:10
NVD link : CVE-2026-38428
Mitre link : CVE-2026-38428
CVE.ORG link : CVE-2026-38428
JSON object : View
Products Affected
kestra
- kestra
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
