{"id":"CVE-2019-12417","aliases":["GHSA-q3p4-gw7r-wqjc","PYSEC-2019-216","PYSEC-2026-617"],"url":"https://o3.security/vulnerability/CVE-2019-12417","summary":"Apache Airflow vulnerable to XSS and local file disclosure","details":"A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.","published":"2019-10-30T22:15:10.807Z","modified":"2026-08-07T15:00:10.205981Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"airflow","fixedVersion":"1.10.6"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/f3aa5ff9c7cdb5424b6463c9013f6cf5db83d26c66ea77130cbbe1bc%40%3Cusers.airflow.apache.org%3E"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:00:10.205981Z"}}