Vulnerability GHSA-9r64-3wmc-x8m8
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
1 year ago
June 26, 2025 at 09:31 PM UTC
Apache Airflow Providers Snowflake package allows for Special Element Injection via CopyFromExternalStageToSnowflakeOperator
1.0.0b1 - 6.4.0rc1
1.0.0b1 - 6.4.0rc1
Summary
Apache Airflow Providers Snowflake package allows for Special Element Injection via CopyFromExternalStageToSnowflakeOperator
Details
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake.
This issue affects Apache Airflow Providers Snowflake: before 6.4.0.
Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflakeOperator to prevent SQL injection Users are recommended to upgrade to version 6.4.0, which fixes the issue.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
9 days ago
No summary available
1.0.0b1 - 6.18.0rc1 PYSEC-2026-4188
1.0.0b1 - 6.18.0rc1 PYSEC-2026-4188
Unknown
1 year ago
No summary available
1.0.0b1 - 6.4.0rc1 PYSEC-2025-51
1.0.0b1 - 6.4.0rc1 PYSEC-2025-51
Impacted packages
Timeline
Published
1 year ago
June 26, 2025 at 09:31 PM UTC
Fixed (6.4.0)
1 year ago
June 18, 2025 at 03:06 PM UTC
Last Modified
1 year ago
June 27, 2025 at 09:41 PM UTC