PyPI: apache-airflow-providers-edge3

CVE-2025-67895

Safety vulnerability ID: SFTY-20251217-91455

Safety legacy ID: pyup.io-82919

Affected versions of the apache-airflow-providers-edge3 package are vulnerable to Remote Code Execution due to an internal, non-public Edge3 testing API being implicitly enabled when the provider is installed and configured on Airflow 2. The Edge3 provider’s “Edge3 Worker RPC” path exposes a normally non-public API surface in Airflow 2 that permits a DAG author to trigger code execution in the webserver context, violating the intended separation between DAG author capabilities and webserver execution.

Created at: Dec 22, 2025Updated at: Dec 22, 2025

Overview

Apache Airflow Providers Edge3 exposes internal API allowing RCE in web server context

Advisory

Affected versions of the apache-airflow-providers-edge3 package are vulnerable to Remote Code Execution due to an internal, non-public Edge3 testing API being implicitly enabled when the provider is installed and configured on Airflow 2. The Edge3 provider’s “Edge3 Worker RPC” path exposes a normally non-public API surface in Airflow 2 that permits a DAG author to trigger code execution in the webserver context, violating the intended separation between DAG author capabilities and webserver execution.

Affected Package

Affecting apache-airflow-providers-edge3 package, versions
<2.0.0

Also affects

---

How to Fix

Upgrade
apache-airflow-providers-edge3
to
2.0.0
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more