Apache Airflow Google provider allows path traversal through GCS object names
🔗 CVE IDs covered (1)
📋 Description
Apache Airflow's Google provider operators GCSToSFTPOperator and GCSTimeSpanFileTransformOperator joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (typically a different trust principal than the DAG author — partner uploads, ingest-only service accounts, public-data buckets) could create an object whose name contains .. segments and cause the DAG run to write the downloaded blob outside the configured destination (the SFTP destination_path for GCSToSFTPOperator; the worker-local temp directory for GCSTimeSpanFileTransformOperator), enabling overwrite of arbitrary files on the SFTP server or the worker host. Affects deployments that ingest from buckets writable by less-trusted principals. Users are advised to upgrade to apache-airflow-providers-google 22.2.1 or later.
🎯 Affected products1
- pip/apache-airflow-providers-google:< 22.2.1
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-49297
- https://github.com/apache/airflow/pull/67667
- https://lists.apache.org/thread/[email protected]
- http://www.openwall.com/lists/oss-security/2026/07/04/8
- https://github.com/apache/airflow/commit/0385bae70553223677753047b3e779d8b86b15c4
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow-providers-google/PYSEC-2026-2084.yaml
- https://github.com/advisories/GHSA-v3mh-27qj-w836