Skip to content
Apache AirflowGHSA-6pw3-8h9w-32gc

Apache Airflow vulnerable to OS Command Injection via example DAGs

High8.8CVE-2022-40127 · Published Nov 14, 2022 · updated May 1, 2025

A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow versions prior to 2.4.0.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.4.02.4.0
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
OS Command Injection in Apache Airflow
Critical9.8Nov 22, 2022
OS Command Injection in Apache Airflow
Critical9.8Nov 22, 2022
OS Command Injection in Apache Airflow
Medium5.5Nov 22, 2022
Apache Airflow Contains Open Redirect
Medium6.1Nov 15, 2022
Apache Airflow subject to Exposure of Sensitive Information
High7.5Nov 14, 2022
Apache Airflow Cross-site Scripting vulnerability
Medium6.1Nov 2, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.