{"id":"CVE-2026-81914","published":"2026-09-29T10:17:12.530","lastModified":"2026-09-29T21:19:31.897","description":"Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the query.\n\nThe names are frequently not written by the Dag author. In a wildcard `gcs_to_gdrive` transfer they come from the source bucket listing, so anyone able to create objects in that bucket controls them — typically an external data producer or an ingest-only service account, a different trust principal from the Dag author. An injected clause can broaden the match and so steer which file or folder the hook resolves: an upload can be directed into a folder the attacker named, and, because downloads select the most recently modified match, a download can return a file they placed rather than the one the Dag asked for.\n\nAffects deployments passing externally-sourced names to the Google Drive hook, including wildcard `gcs_to_gdrive` transfers from buckets writable by less-trusted principals. Users are advised to upgrade to `apache-airflow-providers-google` `22.6.0` or later, which escapes quote and backslash characters in every value interpolated into a Drive query.","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-943"],"vendors":[],"products":[],"references":[{"url":"https://github.com/apache/airflow/pull/72166","tags":[]},{"url":"https://lists.apache.org/thread/90osv795jrqds051y7v3lcdzhsospooo","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/29/13","tags":[]}],"exploitRefs":[{"url":"https://github.com/apache/airflow/pull/72166","tags":[]}],"hasPoc":true,"ai":null}