Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-53543


Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored XSS due to improper handling of HTTP response received. This vulnerability is fixed in 0.22.0.


Published

2025-07-07T20:15:28.323

Last Modified

2025-07-08T16:18:34.923

Status

Awaiting Analysis

Source

[email protected]

Severity

CVSSv3.1: 4.2 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products

-


References