CVE-2026-81914: Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names
Apache Airflow Google provider before 22.6.0 allows Google Drive query injection via unescaped names (CVE-2026-81914).
CVE-2026-81914, rated low, affects the Apache Airflow Google provider before version 22.6.0. Google Drive search expressions were built by interpolating file and folder names into single-quoted string literals without escaping the delimiting quote. A name containing an apostrophe can terminate the literal early and append attacker-chosen clauses to the query. The disclosure does not report exploitation in the wild.
- CVE-2026-81914 is rated low and fixed in Google provider 22.6.0.
- File and folder names were inserted into quoted Drive search literals.
- An apostrophe can break the literal and append attacker-chosen query clauses.
- No in-the-wild exploitation is described.
Vulnerabilities mentionedAll →
- CVE-2026-819144.3—Google Drive query injection in Apache Airflow Google providerpublished · Apache Software Foundation apache-airflow-providers-google
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81914 | Google Drive query injection in Apache Airflow Google provider Apache Airflow's Google provider built Google Drive search expressions by inserting file and folder names into single-quoted string literals without escaping the delimiting quote or backslash. A name containing an apostrophe ends the literal early and appends query clauses chosen by whoever controls that name. Those names are often not written by the Dag author; in a wildcard gcs_to_gdrive transfer they come from the source bucket listing, so a less-trusted principal who can create objects there can broaden the match, send an upload into a folder they named, or cause a download to return a file they placed because downloads select the most recently modified match. Deployments that pass externally sourced names to the Google Drive hook are affected. No public proof of concept is known, the issue is not on the CISA KEV list, and exploitation in the wild is not reported. |
Posted by Shahar Epstein on Sep 29 Severity: low Affected versions: - Apache Airflow Google provider before 22.6.0 Description: Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the...
This source does not provide full text. Read it at seclists.org.