PT-2025-44367 · Apache · Apache Airflow
Nacl
·
Published
2025-10-29
·
Updated
2025-11-06
·
CVE-2025-54941
CVSS v4.0
5.2
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions prior to 3.0.5
Description
A parameter in the
example dag decorator dag was not properly validated, potentially allowing a user of the Airflow UI to redirect the example to a malicious server and execute code on a worker node. This exploitation required that example dags were enabled in a production environment, which is not the default configuration, or that the example dag code was copied to create a similar dag.Recommendations
Review and update the
example dag decorator dag to align with the changes implemented in Airflow 3.0.5.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow