GHSA-86vp-x3pr-79rx
GitHub Security Advisory
Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
The `origin` parameter passed to some of the endpoints like `/trigger` was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.15. This is same as CVE-2020-13944 but the implemented fix in Airflow 1.10.13 did not fix the issue completely.
Affected Packages
PyPI
apache-airflow
Affected versions:
0
(fixed in 1.10.15rc1)
PyPI
apache-airflow
Affected versions:
2.0.0b1
(fixed in 2.0.2rc1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: November 24, 2025 6:09 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.