← voltar
CVE-2026-34612

Kestra: Remote Code Execution via SQL Injection

CVSS 10 CRITICALEPSS 0.7%CWE-89
Vexday Risk Score
28Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 10EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
03 abr 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the following endpoint "GET /api/v1/main/flows/search". Once a user is authenticated, simply visiting a crafted link is enough to trigger the vulnerability. The injected payload is executed by PostgreSQL using COPY ... TO PROGRAM ..., which in turn runs arbitrary OS commands on the host. This issue has been patched in version 1.3.7.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Produtos afetados
kestra-io · kestra

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →