GHSA-52gm-qmg3-r4qp
GitHub Security Advisory
Apache Airflow: XSS vulnerability in Task Instance Log/Log Details
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.
Users are recommended to upgrade to version 2.9.1, which fixes this issue.
Affected Packages
PyPI
apache-airflow
Affected versions:
2.9.0
(fixed in 2.9.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: November 26, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.