CVE-2025-62402
30.10.2025, 10:15
API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available.Enginsight
| Vendor | Product | Version |
|---|---|---|
| apache | airflow | 3.0.0 ≤ 𝑥 < 3.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration