GHSA-v3c9-j6h9-66v4

Suggest an improvement
Source
https://github.com/advisories/GHSA-v3c9-j6h9-66v4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-v3c9-j6h9-66v4/GHSA-v3c9-j6h9-66v4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v3c9-j6h9-66v4
Aliases
Published
2025-10-30T12:31:11Z
Modified
2026-07-07T17:56:51Z
Severity
  • 5.2 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Apache Airflow has a command injection vulnerability in "example_dag_decorator"
Details

An example dag example_dag_decorator had non-validated parameter that allowed the UI user to redirect the example to a malicious server and execute code on worker. This however required that the example dags are enabled in production (not default) or the example dag code copied to build your own similar dag. If you used the example_dag_decorator please review it and apply the changes implemented in Airflow 3.0.5 accordingly.

Database specific
{
    "cwe_ids":  [
        "CWE-78"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-10-30T17:09:19Z",
    "nvd_published_at":  "2025-10-30T10:15:35Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / apache-airflow

Package

Name
apache-airflow
View open source insights on deps.dev
Purl
pkg:pypi/apache-airflow

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.0.5

Affected versions

3.*
3.0.0
3.0.1rc1
3.0.1
3.0.2rc1
3.0.2rc2
3.0.2
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.3
3.0.4rc1
3.0.4rc2
3.0.4
3.0.5rc1
3.0.5rc2
3.0.5rc3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-v3c9-j6h9-66v4/GHSA-v3c9-j6h9-66v4.json"