Vulnerability GHSA-9r64-3wmc-x8m8

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
1 year ago
June 26, 2025 at 09:31 PM UTC
Apache Airflow Providers Snowflake package allows for Special Element Injection via CopyFromExternalStageToSnowflakeOperator
1.0.0b1 - 6.4.0rc1
1.0.0b1 - 6.4.0rc1

Summary

Apache Airflow Providers Snowflake package allows for Special Element Injection via CopyFromExternalStageToSnowflakeOperator

Details

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake.

This issue affects Apache Airflow Providers Snowflake: before 6.4.0.

Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflakeOperator to prevent SQL injection Users are recommended to upgrade to version 6.4.0, which fixes the issue.

Timeline

Published
1 year ago
June 26, 2025 at 09:31 PM UTC
Fixed (6.4.0)
1 year ago
June 18, 2025 at 03:06 PM UTC
Last Modified
1 year ago
June 27, 2025 at 09:41 PM UTC