A vulnerability has been found in kestra-io kestra up to 1.0.42/1.3.18 and classified as critical . The impacted element is the function URI.toString of the component Local Storage Backend . The manipulation leads to path traversal. This vulnerability is uniquely identified as CVE-2026-45807 . The attack is possible to be carried out remotely. No exploit exists. The affected component should be upgraded.