CVE-2025-53543: Kestra-Io Kestra

Medium severity, CVSS 4.2. EPSS: 0.2% chance of exploitation in the next 30 days.

Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored XSS due to improper handling of HTTP response received. This vulnerability is fixed in 0.22.0.

Affected products

  • Kestra-Io Kestra: before 0.22.0 (fixed in 0.22.0)

Published 2025-07-07. Last modified 2026-06-17.