VYPR

Apache Airflow Providers SFTP

by Apache

CVEs (1)

  • CVE-2026-50203CriJun 17, 2026
    risk 0.52cvss 9.1epss 0.01

    A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is…