Kestra configs authentication bypass
Added: 09/04/2026Background
Kestra is open-source software for data, AI, and infrastructure workflows.Problem
An authentication bypass vulnerability in the AuthenticationFilter class allows remote unauthenticated attackers to bypass authentication for any request path ending with "configs", leading to arbitrary command execution.Resolution
Upgrade to Kestra 1.0.45 or 1.3.21 or higher.References
https://github.com/kestra-io/kestra/security/advisories/GHSA-5vc5-wxxq-3fjxBack to exploit index
