Severity: Low 

Affected versions:

- Apache Airflow (apache-airflow) before 3.2.0

Description:

The example example_xcom that was included in airflow documentation implemented 
unsafe pattern of reading value
from xcom in the way that could be exploited to allow UI user who had access to 
modify XComs to perform arbitrary
execution of code on the worker. Since the UI users are already highly trusted, 
this is a Low severity vulnerability.

It does not affect Airflow release - example_dags are not supposed to be 
enabled in production environment, however
users following the example could replicate the bad pattern. Documentation of 
Airflow 3.2.0 contains version of
the example with improved resiliance for that case.

Users who followed that pattern are advised to adjust their implementations 
accordingly.

Credit:

Vincent55 Yang (finder)

References:

https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2025-54550

Reply via email to