CVE-2025-54415 affects the astronomer/dag-factory project, a library used with Apache Airflow to construct DAGs declaratively from configuration files. In versions 0.23.0a8 and earlier, the repository's cicd.yml GitHub Actions workflow is vulnerable when triggered via pull_request_target. The workflow is misconfigured such that attacker-controlled code from a pull request can be executed in the GitHub Actions runner context. Because pull_request_target runs with the security context of the target repository, successful exploitation can lead to arbitrary command execution in the CI environment and access to repository secrets and privileged automation tokens.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is an automated research snapshot of Astronomer's dag-factory Python library, not a conventional standalone exploit toolkit. Its primary code under dagfactory/ builds Apache Airflow DAGs from YAML, supports custom operators, callbacks, dynamic task mapping, datasets, and loading Python callables from configured absolute paths. The dev/ tree supplies Airflow/Docker examples and documentation; docs/ describes the configuration model. The relevant exploit condition is in .github/workflows/cicd.yaml: it is triggered by pull_request_target but repeatedly checks out github.event.pull_request.head.sha. Thus, source supplied by a pull request—including a fork—can influence the code/configuration run by Hatch. The Deploy-Pages job has contents: write, checks out that same PR revision, and invokes Hatch documentation deployment commands, creating a privilege-boundary violation and potential repository-write impact. No hard-coded reverse shell, credential-stealing payload, or external C2 is present. Separately, the library performs opt-out telemetry to Scarf; development examples make requests to PyPI Stats and Hacker News.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.