PT-2026-32992 · Apache · Apache Airflow

·

CVE-2025-54550

·

Published

2026-04-15

·

Updated

2026-07-13

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow (affected versions not specified)
Description An example named 'example xcom' in the documentation implemented an unsafe pattern for reading values from XCom. This could allow a UI user with permissions to modify XComs to execute arbitrary code on the worker. XCom is a mechanism that allows tasks to exchange small amounts of data.
Recommendations Users who implemented the pattern found in the 'example xcom' example should adjust their implementations to match the improved version provided in the Airflow 3.2.0 documentation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2025-54550
CVE-2025-54550
ECHO-968F-A05C-4A8B
GHSA-Q2HG-643C-GW8H
PYSEC-2026-2353

Affected Products

Apache Airflow