CVE-2025-50213
Published: 24 June 2025
Summary
CVE-2025-50213 is a critical-severity Special Element Injection (CWE-75) vulnerability in Apache Apache-Airflow-Providers-Snowflake. Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 34.1% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-19239
Vulnerability details
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflakeOperator to prevent SQL…
more
injection Users are recommended to upgrade to version 6.4.0, which fixes the issue.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.