CyberRota Analysis
AI-GeneratedA critical vulnerability in Apache Airflow allows attackers to exploit the `BaseSerialization.deserialize()` method, enabling remote code execution via malicious class paths embedded in serialized Directed Acyclic Graphs (DAGs). This breach compromises the security boundary by allowing unauthorized code execution within the API Server and Scheduler processes. Organizations using Apache Airflow, especially those with limited trust in DAG authors, should prioritize upgrading to version 3.3.0 or later and consider implementing strict deserialization class allowlists as a mitigation strategy.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server / Scheduler process, crossing the Airflow security boundary that DAG-author code must never execute in those processes. Users are advised to upgrade to `apache-airflow` 3.3.0 or later. As a defense-in-depth mitigation, deployments where DAG-author trust is limited can restrict the `[core] allowed_deserialization_classes` config to a narrow allowlist.
Related CVEs
Other vulnerabilities affecting the same vendor(s)