VYPR

airflow-providers-samba

by Apache

CVEs (1)

  • CVE-2026-49818Jun 9, 2026
    risk 0.00cvss epss

    The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects…