Skip to content
Apache AirflowGHSA-g5hv-r743-v8pm

Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler

High8.8CVE-2024-39877 · Published Jul 17, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
>= 2.4.0, < 2.9.32.9.3
Details and references

Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according to the Airflow Security model. Users should upgrade to version 2.9.3 or later which has removed the vulnerability.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-277, CWE-94
Also known as
BIT-airflow-2024-39877, CVE-2024-39877, PYSEC-2024-190

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Jul 172024Apache Airflow Potential Cross-site Scripting Vulnerability
CVE-2024-39863Medium5.4fixed in 2.9.3
Aug 52024Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB.
CVE-2024-42447Critical9.8no fix yet
Jun 142024Apache Airflow does not return the "Cache-Control" header for dynamic content
CVE-2024-25142Lowfixed in 2.9.2
Aug 212024Apache Airflow Cross-site Scripting Vulnerability
CVE-2024-41937Medium6.1fixed in 2.10.0
Sep 72024Apache Airflow vulnerable to Execution with Unnecessary Privileges
CVE-2024-45034High8.8fixed in 2.10.1
Sep 72024Apache Airflow vulnerable to Improper Encoding or Escaping of Output
CVE-2024-45498High8.8fixed in 2.10.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.