Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra task `inputFiles` writes rendered file names directly under the task working directory. When a flow forwards untrusted execution or webhook data into an `inputFiles` file name, a caller can use `../` path segments to create or overwrite files outside that task working directory on the worker filesystem. Versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43 patch the issue.
References
Configurations
No configuration.
History
23 Jun 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/kestra-io/kestra/security/advisories/GHSA-q3fw-mvgv-pjr2 - |
19 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-19 21:16
Updated : 2026-06-23 03:16
NVD link : CVE-2026-48129
Mitre link : CVE-2026-48129
CVE.ORG link : CVE-2026-48129
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
