PT-2026-37118 · Dagster+4 · Dagster Core+5

·

CVE-2026-41490

·

Published

2026-04-18

·

Updated

2026-07-13

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Dagster Core versions prior to 1.13.1 Dagster libraries versions prior to 0.29.1
Description DuckDB, Snowflake, BigQuery, and DeltaLake I/O managers construct SQL WHERE clauses by interpolating dynamic partition key values into queries without escaping. A user with the Add Dynamic Partitions permission can create a partition key that injects arbitrary SQL, which executes against the target database backend using the I/O manager's credentials. This issue only affects deployments using dynamic partitions; pipelines using static or time-window partitions are not impacted.
Recommendations Update Dagster Core to version 1.13.1. Update Dagster libraries to version 0.29.1.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41490
GHSA-MJW2-V2HM-WJ34
PYSEC-2026-2432
PYSEC-2026-2433
PYSEC-2026-2434
PYSEC-2026-2435
PYSEC-2026-2436
PYSEC-2026-2437

Affected Products

Bigquery
Dagster Core
Dagster Libraries
Deltalake
Duckdb
Snowflake