API Code Execution Vulnerability in Apache Airflow
CVE-2025-62402

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 October 2025

What is CVE-2025-62402?

The vulnerability allows API users to execute arbitrary Dag code within the context of the API server. If the API server is configured in an environment where Dag files are accessible, this could lead to unauthorized manipulation of workflows and execution of untrusted code, potentially compromising the integrity of the system and its data.

Affected Version(s)

Apache Airflow 3.0.0 < 3.1.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kwkr (https://github.com/kwkr)
.
CVE-2025-62402 : API Code Execution Vulnerability in Apache Airflow