Vulnerability record · CVE-2020-11978 · published 17 July 2020
CVE-2020-11978: Apache Airflow example DAG command injection
Apache · Airflow
Apache Airflow 1.10.10 and below ship an example DAG containing an OS command injection flaw. Any authenticated user can execute arbitrary commands as the user running the Airflow worker or scheduler. Deployments with load_examples=False are not affected.
Description
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows authenticated remote code execution, is listed in CISA KEV, and has an EPSS probability near 1.0 with public exploit code available.
What it is
Apache Airflow 1.10.10 and below ship an example DAG containing an OS command injection flaw. Any authenticated user can execute arbitrary commands as the user running the Airflow worker or scheduler. Deployments with load_examples=False are not affected.
Impact
An attacker with a valid Airflow account gains remote code execution with the privileges of the worker or scheduler process, allowing full compromise of the Airflow host and any credentials or data it can reach.
Attack surface
Reachable over the network through the Airflow web interface by an authenticated user; no user interaction beyond normal authenticated access is required. The vulnerable component is the example DAG included by default unless examples are disabled.
Exploitation
CVE-2020-11978 is listed in CISA KEV with a 2022-01-18 addition date, and public exploit code is referenced on Packet Storm. EPSS gives a 30-day exploitation probability of 0.99189 (99.9th percentile), indicating active and widespread exploitation.
What to do
- Upgrade Apache Airflow to a version above 1.10.10 per vendor instructions.
- Set load_examples=False in airflow.cfg to remove the vulnerable example DAGs if upgrading is not immediately possible.
- Restrict Airflow web UI access to trusted networks and remove or disable unused user accounts.
- Run Airflow workers and schedulers with least-privilege service accounts and isolate them from sensitive systems.
- Audit DAG definitions and remove any example or unused DAGs that execute shell commands.
Detection
- Monitor Airflow worker and scheduler process trees for unexpected child processes such as shells or command interpreters.
- Alert on DAG runs of example DAGs, particularly those invoking Bash or Python operators with unusual arguments.
- Review Airflow audit and web access logs for authenticated users triggering example DAGs outside normal schedules.
- Hunt for outbound network connections or file writes originating from Airflow worker/scheduler hosts that deviate from baseline.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-11978 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "Apache Airflow Command Injection". Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162908/Apache-Airflow-1.10.10-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/174764/Apache-Airflow-1.10.10-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://lists.apache.org/thread.html/r7255cf0be3566f23a768e2a04b40fb09e52fcd1872695428ba9afe91%40%3Cusers.airflow.apache | Mailing ListVendor Advisory |
| http://packetstormsecurity.com/files/162908/Apache-Airflow-1.10.10-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/174764/Apache-Airflow-1.10.10-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://lists.apache.org/thread.html/r7255cf0be3566f23a768e2a04b40fb09e52fcd1872695428ba9afe91%40%3Cusers.airflow.apache | Mailing ListVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-11978 | Third Party AdvisoryUS Government Resource |
Track CVE-2020-11978 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-11978), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.