# CVE-2025-50213

## Summary

- **CVE ID:** CVE-2025-50213
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-75
- **Published:** Jun 24, 2025
- **Last Modified:** Mar 12, 2026

## Description

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake.

This issue affects Apache Airflow Providers Snowflake: before 6.4.0.

Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflakeOperator to prevent SQL injection
Users are recommended to upgrade to version 6.4.0, which fixes the issue.

## Affected Products

- Apache Software Foundation — Apache Airflow Providers Snowflake (0)

## References

- [CNA](https://github.com/apache/airflow/pull/51734)
- [CNA](https://lists.apache.org/thread/2kqfmyt2pghg5f6797g8hzvq331v8qx3)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.57%
- **EPSS Percentile:** 45.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._