MEDIUM 6.3 PyPI
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
GHSA-hhm6-jjf4-6pm3 · CVE-2025-27018
Published · Modified
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.
When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended.
It could lead to data corruption, modification and others.
This issue affects Apache Airflow MySQL Provider: before 6.2.0.
Users are recommended to upgrade to version 6.2.0, which fixes the issue.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-27018
- WEB https://github.com/apache/airflow/pull/47254
- WEB https://github.com/apache/airflow/pull/47255
- PACKAGE https://github.com/apache/airflow
- WEB https://lists.apache.org/thread/m8ohgkwz4mq9njohf66sjwqjdy28gvzf
- WEB http://www.openwall.com/lists/oss-security/2025/03/19/4
Ready to move
Start Securing
Free, no credit card | First findings in minutes