Impact
CVE-2024-45498 affects the example_inlet_event_extra.py example DAG shipped with Apache Airflow 2.10.0. Advisory sources describe a command-execution risk for an authenticated user who has DAG trigger permission when the affected example or copied DAG code is present [S2][S4]. Airflow 2.10.1 is the fixed release, and OSV also lists the 2.10.1 release candidate as affected [S3].
Root Cause
The issue is tracked as CWE-116, improper encoding or escaping of output [S1]. In practical deployment terms, the risk is tied to the example DAG code path and the permissions and deployment choices around loaded DAGs, not to every Airflow UI response [S4][S5].
Covered by FixVibe
FixVibe's GitHub repo scans flag Python projects that depend on the apache-airflow release associated with this advisory, and show the version and file to upgrade.
Remediation
Upgrade Apache Airflow to 2.10.1 or a later maintained release, regenerate the active lockfile or constraints file, and rebuild every scheduler, webserver, worker, CI, notebook, and container image that installs Airflow [S2][S3]. Keep example DAGs disabled in production and remove or update any copied example_inlet_event_extra.py DAGs before redeploying.
