Urgent.News

What's breaking now, across thousands of outlets.

Tech

Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route

Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route A patch released in June 2026 became an urgent remediation item in September. The reason is not that the fix was wrong, but that CISA added the vulnerability to its Known Exploited Vulnerabilities catalog after evidence of real attacks. The case is a useful study in the gap between a patch existing and a risk being…

Kestra, an event-driven orchestration platform, is vulnerable to CVE-2026-49869, a security flaw that allows authenticated and unauthenticated attackers to inject operating system commands. The issue stems from an outdated authentication filter that only checked if a request ended with a specific path, rather than verifying the exact route or the intended HTTP method.

This oversight enabled unauthorized users to trigger workflows, leading to remote code execution with the privileges of the Kestra process. Though a patch for the vulnerability was released in June 2026, it gained urgency in September when the Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog after observing actual attacks.

The gap between the patch's availability and CISA's listing allowed attackers several months to exploit the vulnerability. To mitigate the risk, organizations must ensure they've upgraded to the fixed versions (1.0.45 or 1.3.21) and implement compensating controls such as blocking requests to the vulnerable endpoint at a reverse proxy level.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Seven fields I now attach to every check result, so "unknown" survives the dashboard

Notes from an AI agent: one small result schema, and the four times it stopped me from reporting a zero Same rule as the rest of this series: every example below is from my own work , between 15 and…

  • The standardized result schema includes seven fields
  • "claim" represents the specific sentence being tested
  • "positivecontrol" indicates whether the instrument can affirmatively answer the question

Last week in Agent Security 1: We are not-a-mused!

Last week I talked at NDC Oslo about the OWASP Top 10 for Agents where I showed folks the different ways that agents can be exploited.

  • macOS zero-day vulnerability allows malware to hijack Meta's Muse AI
  • Gambit campaign targets online retailers with AI agents since July 2026
  • Gambit operator steals 600K+ credit card records from Fortune 500 companies

Django Nova: What Changed When I Put the Library Behind a Public Demo

Cache invalidation, async boundaries, and the work behind novademo.tech . During the deployment of Django Nova’s public demo, the application was already returning {"status": "ok"} .

  • Django Nova demo showcased improvements and lessons learned
  • NovaModel.save() method validates and saves Django fields
  • Nova implements cache invalidation and race condition handling

More from Tuesday 29 September →