important · Edge — Workflow
Kestra's unauthenticated workflow path is being used to reach worker-container command execution.
Affects
Kestra OSS workflow-orchestration servers, commonly deployed as containers on application and automation infrastructure
Any route ending in /configs escapes the authentication filter, allowing an unauthenticated caller to create and execute a script workflow as uid 0 in the worker container.
Detail and 3 sources
The service is commonly exposed on TCP port 8080 or a mapped container port.
Microsoft observed workflow-origin shell execution, and CISA added the vulnerability to KEV on September 2. Kestra has published a fix.