CVE-2025-62402: Apache Airflow: Airflow 3 API: /api/v2/dagReports executes DAG Python in API
Published Oct 29, 2025
·Updated
API users via /api/v2/dagReports could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available.
Affected Software
3 affected componentsFixes available
Apache Airflow=3
pip/apache-airflow>=3.0.0<3.1.1
3.1.1
Apache Airflow>=3.0.0<3.1.1
Event History
Oct 30, 2025
CVE Published
via MITRE·09:14 AM
Data Sourced
via MITRE·09:14 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·12:31 PM
Data Sourced
via GitHub·12:31 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62402?
CVE-2025-62402 is classified as a critical vulnerability due to the potential for unauthorized code execution.
2
How do I fix CVE-2025-62402?
To remediate CVE-2025-62402, ensure that the API server is not deployed in an environment where Dag files are accessible.
3
Who is affected by CVE-2025-62402?
CVE-2025-62402 affects users of Apache Airflow version 3 that have the API endpoint `/api/v2/dagReports` exposed.
4
What types of attacks can be performed using CVE-2025-62402?
Attackers can perform unauthorized Dag code execution, potentially leading to data breaches or service disruptions.
5
When was CVE-2025-62402 disclosed?
CVE-2025-62402 was disclosed in October 2025.