CVE-2025-27018

CVE-2025-27018: Apache Airflow MySQL Provider: SQL injection in MySQL provider core function

Vendor Apache Software Foundation
Product Apache Airflow MySQL Provider
Weakness CWE-89 · SQLi
Published March 19, 2025
Last update March 25, 2025

CVSS base score

What the vulnerability does

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue.

Key dates

Disclosure timeline

March 19, 2025 CVE published
March 25, 2025 Record updated