CVE-2026-48129

Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra task `inputFiles` writes rendered file names directly under the task working directory. When a flow forwards untrusted execution or webhook data into an `inputFiles` file name, a caller can use `../` path segments to create or overwrite files outside that task working directory on the worker filesystem. Versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43 patch the issue.
Configurations

No configuration.

History

23 Jun 2026, 03:16

Type Values Removed Values Added
References () https://github.com/kestra-io/kestra/security/advisories/GHSA-q3fw-mvgv-pjr2 - () https://github.com/kestra-io/kestra/security/advisories/GHSA-q3fw-mvgv-pjr2 -

19 Jun 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-19 21:16

Updated : 2026-06-23 03:16


NVD link : CVE-2026-48129

Mitre link : CVE-2026-48129

CVE.ORG link : CVE-2026-48129


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')