← Back to browse · API

CVE-2026-5366

Severity
CRITICAL
CVSS
9.9
EPSS
0.00874
Risk score
39.91
CISA KEV
No
PoC
Yes
Published
2026-06-20
Modified
2026-06-22
First seen
2026-08-07
Aliases
EUVD-2026-38128, GHSA-7PM4-56H2-5RXR
Products
prefecthq:prefecthq/prefect unspecified ≤latest
Sources
euvd EUVD-2026-38128
packetstorm d7302741db3c0026fb47cac0|CVE-2026-5366

Description

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to git commands, lacks validation and does not include a `--` separator to distinguish user input from git flags. This allows attackers to inject arbitrary git flags, such as `--upload-pack`, enabling execution of external programs. Additionally, the `directories` parameter can be exploited to inject git flags during sparse-checkout operations. These vulnerabilities allow any user with deployment creation permissions to execute arbitrary commands on worker machines, compromising shared work pools in multi-tenant environments.

References