Executive brief
Apache Airflow is an open-source platform used to schedule and monitor complex workflows. A vulnerability in its Samba provider allows an attacker who can upload files to a source Google Cloud Storage (GCS) bucket to write files to unauthorized locations on a target Samba file share. This could lead to the overwriting of sensitive files or the placement of malicious data on corporate file servers, potentially disrupting operations or compromising data integrity.
Technical details
A path traversal vulnerability (CWE-22) exists in the `GCSToSambaOperator` within the Apache Airflow Samba provider. The `_resolve_destination_path` method joined GCS object names to the SMB destination path without proper normalization or containment checks. An attacker with write access to the source GCS bucket could use '..' path segments in object names to escape the intended `destination_path` and write files to arbitrary locations on the Samba server. The issue is resolved in version 4.12.6 by implementing path normalization and validating that the resolved path remains within the configured destination directory.
Affected products
- Apache Software Foundation apache-airflow-providers-samba < 4.12.6
Timeline
- 2026-06-01: patched: Pull request submitted to fix the issue.
- 2026-06-09: disclosed: Initial advisory publication.
- 2026-06-09: advisory
References
- https://github.com/apache/airflow/pull/67857
- https://lists.apache.org/thread/3vs0m3p51psgf54tts18d6336g24x3sf
- http://www.openwall.com/lists/oss-security/2026/06/09/8
- https://github.com/apache/airflow/commit/bc1df029af15cb1d35d5ca0d33bf9235500137cc
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow-providers-samba/PYSEC-2026-208.yaml