CVE-2025-27018Medium· 6.3▾ SunlitApache Airflow MySQL Provider is Vulnerable to SQL Injection
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.8%
Last analysed / modified upstream
0.8% → 0.9%
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.
When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0.
Users are recommended to upgrade to version 6.2.0, which fixes the issue.
apache-airflow-providers-mysql < 6.2.0Upgrade to a patched release:
apache-airflow-providers-mysql 6.2.0