Skip to content
Apache AirflowGHSA-rvmq-4x66-q7j3

Remote code execution (RCE) in Apache Airflow

High8.8CVE-2020-11978 · Published Jul 27, 2020 · updated Oct 22, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.11rc11.10.11rc1
Details and references

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting `load_examples=False` in the config then you are not vulnerable.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-77, CWE-78
Also known as
BIT-airflow-2020-11978, CVE-2020-11978, PYSEC-2020-14

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Jul 272020Multiple stored XSS in RBAC Admin screens in Apache Airflow
CVE-2020-11983Medium5.4fixed in 1.10.11
Jul 272020Command injection via Celery broker in Apache Airflow
CVE-2020-11981Critical9.8fixed in 1.10.11rc1
Jul 272020Insecure default config of Celery worker in Apache Airflow
CVE-2020-11982Critical9.8fixed in 1.10.11
Jul 272020Stored XSS in Apache Airflow
CVE-2020-9485Medium6.1fixed in 1.10.11
May 62020XSS in Apache Airflow
CVE-2019-12398Medium4.8fixed in 1.10.5
Dec 172020Apache Airflow logs passwords in plaintext
CVE-2020-17511Low2.8fixed in 1.10.13

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.