CVE-2026-45807 | kestra-io kestra up to 1.0.42/1.3.18 Local Storage Backend URI.toString path traversal (GHSA-3529-p4wf-xp79 / EUVD-2026-39921)
A vulnerability has been found in kestra-io kestra up to 1.0.42/1.3.18 and classified as critical. The impacted element is the function URI.toString of the component Local Storage Backend. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-45807. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.