PT-2026-37118 · Dagster+4 · Dagster Core+5

Alexwaira

+2

·

Published

2026-04-18

·

Updated

2026-05-07

·

CVE-2026-41490

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Dagster Core versions prior to 1.13.1 Dagster libraries versions prior to 0.29.1
Description DuckDB, Snowflake, BigQuery, and DeltaLake I/O managers construct SQL WHERE clauses by interpolating dynamic partition key values into queries without escaping. A user with the Add Dynamic Partitions permission can create a partition key that injects arbitrary SQL, which executes against the target database backend using the I/O manager's credentials. This issue only affects deployments using dynamic partitions; pipelines using static or time-window partitions are not impacted.
Recommendations Update Dagster Core to version 1.13.1. Update Dagster libraries to version 0.29.1.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-41490
GHSA-MJW2-V2HM-WJ34

Affected Products

Bigquery
Dagster Core
Dagster Libraries
Deltalake
Duckdb
Snowflake