PT-2026-50220 · Apache Airflow · Apache-Airflow-Providers-Smtp

·

CVE-2026-50203

·

Published

2026-06-17

·

Updated

2026-06-17

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions apache-airflow-providers-sftp versions prior to 5.8.1
Description A path traversal issue exists in the SFTP provider. A malicious or compromised remote SFTP server can write files outside the configured local destination directory by using crafted directory-entry names. This can be triggered through the SFTPHook.retrieve directory() function or the SFTPOperator(operation=get) operator. No account is required for this to occur; the risk applies to any deployment that downloads directories from an untrusted SFTP server.
Recommendations Upgrade to version 5.8.1 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50203
ECHO-82D3-866E-E0F0
GHSA-QF38-JQ28-3CCQ
PYSEC-2026-218

Affected Products

Apache-Airflow-Providers-Smtp