PT-2025-26707 · Apache · Apache Airflow Providers Snowflake

Nhien Pham

+1

·

Published

2025-06-24

·

Updated

2026-06-03

·

CVE-2025-50213

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Apache Airflow Providers Snowflake versions prior to 6.4.0
Description: The issue is related to a Failure to Sanitize Special Elements into a Different Plane, also known as Special Element Injection vulnerability. This vulnerability affects the CopyFromExternalStageToSnowflakeOperator, where sanitation of table and stage parameters was added to prevent SQL injection.
Recommendations: For versions prior to 6.4.0, upgrade to version 6.4.0, which fixes the issue. As a temporary workaround, consider adding sanitation to the table and stage parameters in the CopyFromExternalStageToSnowflakeOperator to prevent SQL injection.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-09076
CVE-2025-50213
GHSA-9R64-3WMC-X8M8
PYSEC-2025-51

Affected Products

Apache Airflow Providers Snowflake