THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-34pm-923j-7wf8 (high) — Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection

[GHSA] GHSA-34pm-923j-7wf8 (high) — Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection

medgithub_advisoriesPublished 2026-08-18

GHSA-34pm-923j-7wf8 Severity: high CVE: CVE-2026-55839

Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection

## Summary

Kestra’s Markdown renderer supports a custom `[[link ...]]` syntax that is converted into a custom HTML element. The custom Markdown parser allows attacker-controlled attributes to be rendered into the generated element without proper allowlisting or

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-34pm-923j-7wf8