GHSA-273c-4g26-4jpm

Suggest an improvement
Source
https://github.com/advisories/GHSA-273c-4g26-4jpm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-273c-4g26-4jpm/GHSA-273c-4g26-4jpm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-273c-4g26-4jpm
Aliases
Downstream
Published
2025-10-30T12:31:11Z
Modified
2025-11-06T13:59:33.774698Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Details

API users via /api/v2/dagReports could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available.

Database specific
{
    "cwe_ids": [
        "CWE-250"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2025-10-30T17:08:56Z",
    "nvd_published_at": "2025-10-30T10:15:35Z"
}
References

Affected packages

PyPI / apache-airflow

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.1.1

Affected versions

3.*
3.0.0
3.0.1rc1
3.0.1
3.0.2rc1
3.0.2rc2
3.0.2
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.3
3.0.4rc1
3.0.4rc2
3.0.4
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.5
3.0.6rc1
3.0.6rc2
3.0.6
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.0
3.1.1rc1
3.1.1rc2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-273c-4g26-4jpm/GHSA-273c-4g26-4jpm.json"