PT-2026-32992 · Apache · Apache Airflow
Vincent55 Yang
·
Published
2026-04-15
·
Updated
2026-04-18
·
CVE-2025-54550
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow (affected versions not specified)
Description
An example named 'example xcom' in the documentation implemented an unsafe pattern for reading values from XCom. This could allow a UI user with permissions to modify XComs to execute arbitrary code on the worker. XCom is a mechanism that allows tasks to exchange small amounts of data.
Recommendations
Users who implemented the pattern found in the 'example xcom' example should adjust their implementations to match the improved version provided in the Airflow 3.2.0 documentation.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow