Executive brief
Kestra, an open-source orchestration and scheduling platform, is vulnerable to a critical security flaw that allows attackers to execute unauthorized commands on the underlying server. By sending a specially crafted web request to the application's search interface, an attacker can bypass security controls to access, modify, or delete sensitive database information and take full control of the host system. This could lead to a total compromise of the platform, data theft, and disruption of automated business workflows.
Technical details
A SQL injection vulnerability exists in Kestra's `/api/v1/main/flows/search` endpoint due to improper sanitization of the `filters[labels]` GET parameter. The application directly concatenates user-controlled input into a JSONB containment expression within the `PostgresFlowRepositoryService.findCondition` method. An attacker can use stacked queries to break out of the intended SQL statement. On PostgreSQL installations, this can be escalated to Remote Code Execution (RCE) using the `COPY ... TO PROGRAM` command. On H2 installations, RCE is possible via the `FILE_WRITE` function. While some advisories suggest authentication is required, the NVD-provided CVSS score of 9.8 indicates it may be exploitable without privileges in certain configurations. The issue is patched in version 1.3.7 and backported to 1.0.35.
Affected products
- Kestra Kestra <= 1.3.6
Timeline
- 2026-03-30: advisory: Vendor security advisory published via GitHub
- 2026-05-05: disclosed: CVE-2026-38428 published