PT-2025-44367 · Apache · Apache Airflow

Nacl

·

Published

2025-10-29

·

Updated

2025-11-06

·

CVE-2025-54941

CVSS v4.0

5.2

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.0.5
Description A parameter in the example dag decorator dag was not properly validated, potentially allowing a user of the Airflow UI to redirect the example to a malicious server and execute code on a worker node. This exploitation required that example dags were enabled in a production environment, which is not the default configuration, or that the example dag code was copied to create a similar dag.
Recommendations Review and update the example dag decorator dag to align with the changes implemented in Airflow 3.0.5.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2025-54941
CVE-2025-54941
GHSA-V3C9-J6H9-66V4

Affected Products

Apache Airflow