A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.
Source: NVD ↗ · CISA KEV Catalog ↗