CVE-2026-5366
prefecthq prefecthq/prefect, prefect
Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to git commands, lacks validation and does not include a `--` separator to distinguish user input from git flags. This allows attackers to inject arbitrary git flags, such as `--upload-pack`, enabling execution of external programs. Additionally, the `directories` parameter can be exploited to inject git flags during sparse-checkout operations. These vulnerabilities allow any user with deployment cre...
- CVSS
- 9.9
- EPSS
- 0.87% 55.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.21