VYPR
Medium severity4.2OSV Advisory· Published Jul 7, 2025· Updated Jun 17, 2026

CVE-2025-53543

CVE-2025-53543

Description

Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored XSS due to improper handling of HTTP response received. This vulnerability is fixed in 0.22.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Kestra/KestraOSV2 versions
    v0.19.0, v0.22.0-rc1-SNAPSHOT, v0.22.0-rc2-SNAPSHOT, …+ 1 more
    • (no CPE)range: v0.19.0, v0.22.0-rc1-SNAPSHOT, v0.22.0-rc2-SNAPSHOT, …
    • (no CPE)range: <0.22.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.