PT-2026-36755 · Prefecthq · Prefect
Nedlir
·
Published
2026-05-04
·
Updated
2026-05-04
·
CVE-2026-7725
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PrefectHQ prefect versions prior to 3.6.25.dev7
Description
An argument injection issue exists in the GitRepository Pull Handler component within the
src/prefect/runner/storage.py file. Remote attackers can exploit this by manipulating the commit sha or directories arguments.Recommendations
Upgrade to version 3.6.25.dev7.
Exploit
Fix
Argument Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Prefect