Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  Github GHSA | GHSA-v3c9-j6h9-66v4 | Apache Airflow has a command injection vulnerability in "example_dag_decorator" | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 30 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 
 | 
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Apache Apache airflow | |
| Vendors & Products | Apache Apache airflow | 
Thu, 30 Oct 2025 10:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An example dag `example_dag_decorator` had non-validated parameter that allowed the UI user to redirect the example to a malicious server and execute code on worker. This however required that the example dags are enabled in production (not default) or the example dag code copied to build your own similar dag. If you used the `example_dag_decorator` please review it and apply the changes implemented in Airflow 3.0.5 accordingly. | |
| Title | Apache Airflow: Command injection in "example_dag_decorator" | |
| Weaknesses | CWE-78 | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-10-31T03:55:26.331Z
Reserved: 2025-08-01T06:55:04.376Z
Link: CVE-2025-54941
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-30T19:23:25.927Z
 NVD
                        NVD
                    Status : Undergoing Analysis
Published: 2025-10-30T10:15:35.530
Modified: 2025-10-30T20:15:39.070
Link: CVE-2025-54941
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    Updated: 2025-10-30T14:37:13Z