PT-2025-45771 · Pypi · Apache Airflow

Published

2025-10-30

·

Updated

2025-10-30

CVSS v4.0

5.2

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
An example dag example dag decorator had non-validated parameter that allowed the UI user to redirect the example to a malicious server and execute code on worker. This however required that the example dags are enabled in production (not default) or the example dag code copied to build your own similar dag. If you used the example dag decorator please review it and apply the changes implemented in Airflow 3.0.5 accordingly.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-V3C9-J6H9-66V4

Affected Products

Apache Airflow