Executive brief
Apache Airflow's Google Cloud Storage (GCS) integration operators are used to transfer data from GCS buckets to SFTP servers or local worker directories. An attacker with write access to a source GCS bucket can craft object names containing path-traversal sequences (like "..") to cause downloaded files to be written outside the intended destination directory, potentially overwriting critical files on SFTP servers or Airflow worker hosts.
Technical details
This is a path traversal vulnerability (CWE-22) affecting two Google Cloud Storage operators in Apache Airflow. The vulnerable operators—`GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator`—compute filesystem destination paths by joining GCS object names (returned from bucket listing APIs) directly to a configured base path without path normalization or containment checks. Because GCS object names are arbitrary UTF-8 strings controlled by whoever can write to the source bucket, an attacker can embed ".." directory-traversal sequences or absolute path prefixes in object names. When these names are joined to the base destination path using `os.path.join()`, the resulting path can resolve to locations outside the intended directory—for example, overwriting `~/.ssh/authorized_keys` on an SFTP server or other sensitive files on the worker host. The fix, released in version 22.2.1, normalizes the joined path using `os.path.normpath()` and validates that the final resolved path stays within the configured base directory, raising a `ValueError` if traversal is detected.
Affected products
- Apache Airflow Google provider < 22.2.1
Timeline
- 2026-07-06: disclosed: Vulnerability published by Apache Airflow via GitHub Advisory and NVD
- 2026-06-17: patched: Fix merged in commit 0385bae; version 22.2.1 released with patch
- 2026-07-04: advisory: Advisory posted to oss-security mailing list by Shahar Epstein
References
- https://github.com/apache/airflow/pull/67667
- https://lists.apache.org/thread/cb5nvoxsj1q7rv878cyqgtg150w0zglq?users@airflow.apache.org
- http://www.openwall.com/lists/oss-security/2026/07/04/8
- https://github.com/apache/airflow/commit/0385bae70553223677753047b3e779d8b86b15c4
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow-providers-google/PYSEC-2026-2084.yaml