Executive brief
Kestra OSS is a workflow automation platform used to orchestrate data pipelines and business processes. An unauthenticated attacker can inject arbitrary operating system commands through workflow creation, leading to unauthorized code execution on the server. This vulnerability is already being exploited in active attacks and could enable attackers to take full control of the Kestra server and any connected systems.
Technical details
Kestra OSS contains an OS command injection vulnerability in its workflow execution component. The vulnerability stems from insufficient input validation when processing workflow definitions, allowing an attacker to inject malicious OS commands that are executed with the privileges of the Kestra process. The attack requires no authentication and can be triggered remotely via the workflow creation API. An attacker can achieve arbitrary code execution on the target system, potentially leading to lateral movement, data exfiltration, or system compromise. The vulnerability is confirmed to be actively exploited in the wild. Patch availability should be confirmed through official Kestra security advisories.
Affected products
- Kestra Kestra OSS
Timeline
- 2026-09-02: disclosed
- exploited: Confirmed exploitation in the wild