CRITICALPyPI

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.

CVE-2024-28423Published 2 years agoUpdated 6 days agoSource: OSV

Affected packages

  • airflow-diagramsall versions

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.77%
EPSS percentile
52.2%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 52%.

Recommended response stack

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

Get incidents like this as alerts for your stack.

Join the beta
Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at | HackTribune