PT-2025-44367 · Apache · Apache Airflow

·

CVE-2025-54941

·

Published

2025-10-29

·

Updated

2026-07-07

CVSS v4.0

5.2

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.0.5
Description A parameter in the example dag decorator dag was not properly validated, potentially allowing a user of the Airflow UI to redirect the example to a malicious server and execute code on a worker node. This exploitation required that example dags were enabled in a production environment, which is not the default configuration, or that the example dag code was copied to create a similar dag.
Recommendations Review and update the example dag decorator dag to align with the changes implemented in Airflow 3.0.5.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2025-54941
CVE-2025-54941
GHSA-V3C9-J6H9-66V4
PYSEC-2026-1135

Affected Products

Apache Airflow