dagster vulnerabilities
CVEs whose affected-version data names the dagster package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-41490High· 8.3PoCDagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
▾ Midnightdagster-duckdb · dagster-duckdbEPSS 0.27%via OSV
CVE-2023-51232High· 7.5Dagster vulnerable to Path Traversal attack through its /logs endpoint
Dagster vulnerable to Path Traversal attack through its /logs endpoint
▾ Twilightdagster · dagsterEPSS 0.92%via OSV