PT-2026-32992 · Apache · Apache Airflow

Vincent55 Yang

·

Published

2026-04-15

·

Updated

2026-04-18

·

CVE-2025-54550

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow (affected versions not specified)
Description An example named 'example xcom' in the documentation implemented an unsafe pattern for reading values from XCom. This could allow a UI user with permissions to modify XComs to execute arbitrary code on the worker. XCom is a mechanism that allows tasks to exchange small amounts of data.
Recommendations Users who implemented the pattern found in the 'example xcom' example should adjust their implementations to match the improved version provided in the Airflow 3.2.0 documentation.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2025-54550
CVE-2025-54550
GHSA-Q2HG-643C-GW8H

Affected Products

Apache Airflow