A AegiFlow
MEDIUMCVSS 6.5EPSS 0.7%

CVE-2026-49818

CVE-2026-49818 updated by NVD

Published
2026-06-09
Modified
2026-07-31
EPSS percentile
49%
Sources
github-advisory, nvd

Summary

The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects into the source GCS bucket — typically an external data producer distinct from the trusted DAG author — could write files to arbitrary locations on the Samba target when the operator ran. Upgrade apache-airflow-providers-samba to 4.12.6 or later, which validates the resolved destination stays within `destination_path`.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIapache-airflow-providers-samba4.12.6

Remediation: Upgrade to 4.12.6 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.