{"id":"CVE-2025-30473","aliases":["GHSA-5r62-mjf5-xwhj","PYSEC-2026-1145"],"url":"https://o3.security/vulnerability/CVE-2025-30473","summary":"Apache Airflow Common SQL Provider: Remote Code Execution via Sql Injection","details":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider.\n\nWhen using the partition clause in SQLTableCheckOperator as parameter (which was a recommended pattern), Authenticated UI User could inject arbitrary SQL command when triggering DAG exposing partition_clause to the user.\nThis allowed the DAG Triggering user to escalate privileges to execute those arbitrary commands which they normally would not have.\n\n\nThis issue affects Apache Airflow Common SQL Provider: before 1.24.1.\n\nUsers are recommended to upgrade to version 1.24.1, which fixes the issue.","published":"2025-04-07T08:31:57.220Z","modified":"2026-08-08T03:48:13.102054618Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"apache-airflow-providers-common-sql","fixedVersion":"1.24.1"}],"fix":{"url":"https://github.com/apache/airflow/pull/48098","label":"apache/airflow#48098"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/04/04/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/04/06/1"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/04/06/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/04/06/3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30473.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/53klkv790cylqcop0350w7nfq1y6h0t2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30473"},{"type":"FIX","url":"https://github.com/apache/airflow/pull/48098"},{"type":"PACKAGE","url":"https://pypi.org/project/apache-airflow-providers-common-sql/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:13.102054618Z"}}