Vulnerability Details CVE-2025-50213
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake.
This issue affects Apache Airflow Providers Snowflake: before 6.4.0.
Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflakeOperator to prevent SQL injection
Users are recommended to upgrade to version 6.4.0, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 23.3%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2025-50213
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:1.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:1.1.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:1.1.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:1.2.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:1.3.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.1.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.1.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.2.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.3.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.3.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.4.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.5.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.5.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.5.2
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.6.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:2.7.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:3.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:3.1.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:3.2.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:3.3.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.0.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.0.2
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.0.3
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.0.4
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.0.5
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.1.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.2.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.3.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.3.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.4.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.4.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:4.4.2
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.0.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.1.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.1.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.1.2
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.2.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.2.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.3.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.3.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.4.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.5.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.5.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.5.2
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.6.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.6.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.7.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.7.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.8.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:5.8.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:6.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:6.1.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:6.1.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:6.2.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:6.2.1
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:6.2.2
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:6.3.0
-
cpe:2.3:a:apache:apache-airflow-providers-snowflake:6.3.1