← Vulnerability feed

Vulnerability record · CVE-2020-11978 · published 17 July 2020

CVE-2020-11978: Apache Airflow example DAG command injection

Apache · Airflow

Apache Airflow 1.10.10 and below ship an example DAG containing an OS command injection flaw. Any authenticated user can execute arbitrary commands as the user running the Airflow worker or scheduler. Deployments with load_examples=False are not affected.

8.8 CVSS 3.1 High CISA KEV since 18 Jan 2022 EPSS 99% · top 0.1% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 6.5
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw allows authenticated remote code execution, is listed in CISA KEV, and has an EPSS probability near 1.0 with public exploit code available.

What it is

Apache Airflow 1.10.10 and below ship an example DAG containing an OS command injection flaw. Any authenticated user can execute arbitrary commands as the user running the Airflow worker or scheduler. Deployments with load_examples=False are not affected.

Impact

An attacker with a valid Airflow account gains remote code execution with the privileges of the worker or scheduler process, allowing full compromise of the Airflow host and any credentials or data it can reach.

Attack surface

Reachable over the network through the Airflow web interface by an authenticated user; no user interaction beyond normal authenticated access is required. The vulnerable component is the example DAG included by default unless examples are disabled.

Exploitation

CVE-2020-11978 is listed in CISA KEV with a 2022-01-18 addition date, and public exploit code is referenced on Packet Storm. EPSS gives a 30-day exploitation probability of 0.99189 (99.9th percentile), indicating active and widespread exploitation.

What to do

  • Upgrade Apache Airflow to a version above 1.10.10 per vendor instructions.
  • Set load_examples=False in airflow.cfg to remove the vulnerable example DAGs if upgrading is not immediately possible.
  • Restrict Airflow web UI access to trusted networks and remove or disable unused user accounts.
  • Run Airflow workers and schedulers with least-privilege service accounts and isolate them from sensitive systems.
  • Audit DAG definitions and remove any example or unused DAGs that execute shell commands.

Detection

  • Monitor Airflow worker and scheduler process trees for unexpected child processes such as shells or command interpreters.
  • Alert on DAG runs of example DAGs, particularly those invoking Bash or Python operators with unusual arguments.
  • Review Airflow audit and web access logs for authenticated users triggering example DAGs outside normal schedules.
  • Hunt for outbound network connections or file writes originating from Airflow worker/scheduler hosts that deviate from baseline.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-11978 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "Apache Airflow Command Injection". Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11978 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-13927Apache Airflow Experimental API missing authentication by defaultAirflow's Experimental API defaulted to allowing all requests without authentication, so any reachable instance exposed its API to unauthenticated ca…KEVEPSS 100%analysed9.8CVE-2026-33264Apache airflow deserialization of untrusted data vulnerabilityA bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server …EPSS 1.6%9.8CVE-2023-25754Apache airflow vulnerabilityPrivilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.EPSS 2.3%9.8CVE-2023-22884Apache airflow command injection vulnerabilityImproper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach…EPSS 11%9.8CVE-2022-40189Apache airflow os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl…EPSS 4.1%9.8CVE-2022-38649Apache airflow os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air…EPSS 3.3%9.8CVE-2022-38054Apache airflow vulnerabilityIn Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.EPSS 2.1%9.8CVE-2021-38540Apache Airflow variable import endpoint missing authenticationThe variable import endpoint in Apache Airflow 2.0.0 through 2.1.3 was not protected by authentication. Unauthenticated users could reach it to add o…EPSS 81%analysed

Source: NIST National Vulnerability Database (record CVE-2020-11978), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.