Apache Airflow prior to version 2.2.4 is vulnerable to OS command injection attacks because some example DAGs do not properly sanitize user-provided parameters, making them susceptible to OS Command Injection from the web UI.
id: CVE-2022-24288
info:
name: Apache Airflow OS Command Injection
author: xeldax
severity: h
...