{"apiVersion":"1.0","identifier":"CVE-2026-55839","description":"Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra-s custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaScript event-handler attributes through the custom [[link]] syntax, causing stored cross-site scripting when another user opens the description or information panel in the Flow list. This issue is fixed in version 1.3.24.","publishedAt":"2026-08-18T16:17:53","lastModifiedAt":"2026-08-18T18:18:32","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55839","cvssScore":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","epssProbability":0.00302,"riskScore":0.89,"affectedProduct":"Kestra","affectedVersions":"<1.3.24","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-55839","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-55839","en":"https://www.redsauce.net/en/cves/CVE-2026-55839","fr":"https://www.redsauce.net/fr/cves/CVE-2026-55839","pt":"https://www.redsauce.net/pt/cves/CVE-2026-55839","de":"https://www.redsauce.net/de/cves/CVE-2026-55839","sk":"https://www.redsauce.net/sk/cves/CVE-2026-55839","el":"https://www.redsauce.net/el/cves/CVE-2026-55839"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-55839"}}