Junglewise Threat Intelligence

CVE-2026-34612: Kestra SQL injection in flow search leads to RCE

CVE-2026-34612 · Severity: critical · CVSS 9.9 · Published 2026-04-03

Technologies: Kestra-Io Kestra. Vendors: Kestra.

Executive brief

Kestra is an open-source platform used by businesses to automate and orchestrate complex data workflows. A security flaw in the platform's search feature allows an authenticated user to execute unauthorized commands on the underlying server by clicking a specially crafted link. This could lead to a total system takeover, theft of sensitive operational data, or disruption of automated business processes.

Technical details

A SQL injection vulnerability exists in the 'GET /api/v1/main/flows/search' endpoint due to improper neutralization of the 'labels' filter parameters. In the 'PostgresFlowRepositoryService.findCondition' method, label keys and values are concatenated directly into a JSONB containment expression string without parameter binding. An attacker can break out of the JSON string to execute stacked queries. In the default Docker deployment using PostgreSQL, this is escalated to Remote Code Execution (RCE) via the 'COPY ... TO PROGRAM' command. The vulnerability also affects H2-backed deployments via 'FILE_WRITE()'. Exploitation requires authentication but can be triggered via a crafted link (Cross-Site Request Forgery style). The issue is patched in version 1.3.7.

Affected products

  • kestra-io Kestra < 1.3.7

Timeline

  • 2026-03-30: advisory: Internal advisory published by vendor
  • 2026-03-30: patched: Fix committed to repository
  • 2026-04-01: patched: Version 1.3.7 released
  • 2026-04-03: disclosed: CVE published to NVD

References

Related threats