MEDIUM 4.3 NVD
CVE-2026-81914
Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, witho
Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the query.
The names are frequently not written by the Dag author. In a wildcard `gcs_to_gdrive` transfer they come from the source bucket listing, so anyone able to create objects in that bucket controls them — typically an external data producer or an ingest-only service account, a different trust principal from the Dag author. An injected clause can broaden the match and so steer which file or folder the hook resolves: an upload can be directed into a folder the attacker named, and, because downloads select the most recently modified match, a download can return a file they placed rather than the one the Dag asked for.
Affects deployments passing externally-sourced names to the Google Drive hook, including wildcard `gcs_to_gdrive` transfers from buckets writable by less-trusted principals. Users are advised to upgrade to `apache-airflow-providers-google` `22.6.0` or later, which escapes quote and backslash characters in every value interpolated into a Drive query.
References
- https://github.com/apache/airflow/pull/72166
- https://lists.apache.org/thread/90osv795jrqds051y7v3lcdzhsospooo
- http://www.openwall.com/lists/oss-security/2026/09/29/13
- https://www.openwall.com/lists/oss-security/2026/09/29/13
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-09-29 via NVD.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.