Vulnerability PYSEC-2025-51
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 year ago
June 24, 2025 at 08:15 AM UTC
No summary available
1.0.0b1 - 6.4.0rc1
1.0.0b1 - 6.4.0rc1
Details
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake.
This issue affects Apache Airflow Providers Snowflake: before 6.4.0.
Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflakeOperator to prevent SQL injection Users are recommended to upgrade to version 6.4.0, which fixes the issue.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
9 days ago
No summary available
1.0.0b1 - 6.18.0rc1 PYSEC-2026-4188
1.0.0b1 - 6.18.0rc1 PYSEC-2026-4188
Critical
1 year ago
Apache Airflow Providers Snowflake package allows for Special Element Injection via CopyFromExternalStageToSnowflakeOperator
1.0.0b1 - 6.4.0rc1 GHSA-9r64-3wmc-x8m8
1.0.0b1 - 6.4.0rc1 GHSA-9r64-3wmc-x8m8
Impacted packages
Timeline
Published
1 year ago
June 24, 2025 at 08:15 AM UTC
Fixed (6.4.0)
1 year ago
June 18, 2025 at 03:06 PM UTC
Last Modified
3 months ago
June 10, 2026 at 05:00 PM UTC