CVE-2026-50203Disclosure(apache / apache-airflow-providers-sftp)
LOWCVSS 9.1 · CRITICALSignal is active with 1 mentions in latest observed window
Immediate actions
- Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment downloading directories from an untrusted SFTP server. Upgrade `apache-airflow-providers-sftp` to 5.8.1 or later.
0.0/ 10 priority
Sources & remediation
Patch / fix
Vendor / third-party advisories
Weakness type (CWE)
CWE-22
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
NONE
Are you affected?
If you run products in this scope, you should treat this CVE as relevant to your environment.
- apache-airflow-providers-sftp
Threat summary
- 1 mentions across 1 observed day
What's happening
- Technical details provided in 1 signal
- Disclosure: 1 classified signal
- 1 total mentions across 1 day
Affected systems
Vendors
Products
apache-airflow-providers-sftp
Deep dive
Activity timeline1 mentions / 1d
Signal classification1 categories
Disclosure1100.0%
Referenced assets1 URL
CPE platform detail1 entries
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | apache | apache-airflow-providers-sftp | - | - | - |
