Description
Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the query.

The names are frequently not written by the Dag author. In a wildcard `gcs_to_gdrive` transfer they come from the source bucket listing, so anyone able to create objects in that bucket controls them — typically an external data producer or an ingest-only service account, a different trust principal from the Dag author. An injected clause can broaden the match and so steer which file or folder the hook resolves: an upload can be directed into a folder the attacker named, and, because downloads select the most recently modified match, a download can return a file they placed rather than the one the Dag asked for.

Affects deployments passing externally-sourced names to the Google Drive hook, including wildcard `gcs_to_gdrive` transfers from buckets writable by less-trusted principals. Users are advised to upgrade to `apache-airflow-providers-google` `22.6.0` or later, which escapes quote and backslash characters in every value interpolated into a Drive query.
Published: 2026-09-29
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Patch Now
AI Analysis

Impact

Apache Airflow's Google provider builds Google Drive search expressions by interpolating file and folder names directly into single-quoted strings without escaping quote characters. A name containing an apostrophe terminates the literal early and allows an adversary to append arbitrary clauses to the query, effectively performing a logical injection. This flaw was identified as CWE‑943 and can cause the provider to resolve uploads or downloads to attacker‑controlled folders or files, enabling the execution of unwanted data transfers and potentially exposing or replacing sensitive content.

Affected Systems

The vulnerability affects deployments of the Apache Airflow Google provider through older provider versions before 22.6.0 that send externally sourced file or folder names to the Google Drive hook. Commonly impacted scenarios include wildcard "gcs_to_gdrive" transfers where the source bucket is writable by principals other than the DAG author.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in CISA's KEV catalog, indicating a low to moderate probability of discovery and exploitation. However, exploitation requires the ability to create or modify objects in the source bucket; this is often granted to external data producers or ingest‑only service accounts. The attack vector is therefore an internal or coordinated external actor with write access to the bucket, which appends a maliciously crafted object name. If successful, the hacker can steer uploads to a chosen folder or cause downloads to return attacker‑placed files, leading to unauthorized data access or manipulation.

Generated by OpenCVE AI on September 29, 2026 at 15:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to apache-airflow-providers-google version 22.6.0 or later, which properly escapes quote and backslash characters in Drive queries.
  • Restrict write permissions on source buckets used by gcs_to_gdrive transfers to trusted principals only, ensuring the DAG author is the sole entity that can create object names used in queries.
  • Review DAG definitions to avoid passing unsanitized file or folder names from external sources. Implement defensive validation or sanitization before the values are sent to the Google Drive hook.

Generated by OpenCVE AI on September 29, 2026 at 15:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the query. The names are frequently not written by the Dag author. In a wildcard `gcs_to_gdrive` transfer they come from the source bucket listing, so anyone able to create objects in that bucket controls them — typically an external data producer or an ingest-only service account, a different trust principal from the Dag author. An injected clause can broaden the match and so steer which file or folder the hook resolves: an upload can be directed into a folder the attacker named, and, because downloads select the most recently modified match, a download can return a file they placed rather than the one the Dag asked for. Affects deployments passing externally-sourced names to the Google Drive hook, including wildcard `gcs_to_gdrive` transfers from buckets writable by less-trusted principals. Users are advised to upgrade to `apache-airflow-providers-google` `22.6.0` or later, which escapes quote and backslash characters in every value interpolated into a Drive query.
Title Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names
Weaknesses CWE-943
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-29T20:03:23.525Z

Reserved: 2026-08-27T18:22:42.521Z

Link: CVE-2026-81914

cve-icon Vulnrichment

Updated: 2026-09-29T11:08:14.970Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T10:17:12.530

Modified: 2026-09-29T15:53:48.653

Link: CVE-2026-81914

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T15:45:18Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic