Skip to content
Apache AirflowGHSA-w7cp-g8v7-r54m

Apache Airflow Cross-site Scripting Vulnerability

Medium6.1CVE-2024-41937 · Published Aug 21, 2024 · updated Sep 10, 2026

Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execute a cross-site scripting attack when clicking on a provider documentation link. This would require the provider to be installed on the web server and the user to click the provider link. Users should upgrade to 2.10.0 or later, which fixes this vulnerability.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.10.02.10.0
Details and references

More Apache Airflow advisories

All Apache Airflow

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.