PT-2025-26707 · Apache · Apache Airflow Providers Snowflake

·

CVE-2025-50213

·

Published

2025-06-24

·

Updated

2026-06-03

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Apache Airflow Providers Snowflake versions prior to 6.4.0
Description: The issue is related to a Failure to Sanitize Special Elements into a Different Plane, also known as Special Element Injection vulnerability. This vulnerability affects the CopyFromExternalStageToSnowflakeOperator, where sanitation of table and stage parameters was added to prevent SQL injection.
Recommendations: For versions prior to 6.4.0, upgrade to version 6.4.0, which fixes the issue. As a temporary workaround, consider adding sanitation to the table and stage parameters in the CopyFromExternalStageToSnowflakeOperator to prevent SQL injection.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09076
CVE-2025-50213
GHSA-9R64-3WMC-X8M8
PYSEC-2025-51

Affected Products

Apache Airflow Providers Snowflake