THREAT OPS › Threat News › [GHSA] GHSA-34pm-923j-7wf8 (high) — Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
[GHSA] GHSA-34pm-923j-7wf8 (high) — Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
GHSA-34pm-923j-7wf8 Severity: high CVE: CVE-2026-55839
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
## Summary
Kestra’s Markdown renderer supports a custom `[[link ...]]` syntax that is converted into a custom HTML element. The custom Markdown parser allows attacker-controlled attributes to be rendered into the generated element without proper allowlisting or
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-55839cve
Original source: https://github.com/advisories/GHSA-34pm-923j-7wf8