← Back

CVE-2025-53543

nvd nist
Published: Jul 7, 2025Modified: Jun 17, 2026Deferred

JSON object

Loading...
4.2
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Exploitability: 0.6 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored XSS due to improper handling of HTTP response received. This vulnerability is fixed in 0.22.0.

References (1)

Timeline

No history available yet.