CVE-2025-50213

CVE-2025-50213: Apache Airflow Providers Snowflake: Potential SQL injection in CopyFromExternalStageToSnowflakeOperator

Vendor Apache Software Foundation
Product Apache Airflow Providers Snowflake
Weakness CWE-75
Published June 24, 2025
Last update June 24, 2025

CVSS base score

What the vulnerability does

Description

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflakeOperator to prevent SQL injection Users are recommended to upgrade to version 6.4.0, which fixes the issue.

Key dates

Disclosure timeline

June 24, 2025 CVE published
June 24, 2025 Record updated