PT-2026-36755 · Prefecthq · Prefect

Nedlir

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-7725

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PrefectHQ prefect versions prior to 3.6.25.dev7
Description An argument injection issue exists in the GitRepository Pull Handler component within the src/prefect/runner/storage.py file. Remote attackers can exploit this by manipulating the commit sha or directories arguments.
Recommendations Upgrade to version 3.6.25.dev7.

Exploit

Fix

Argument Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7725
GHSA-6RCX-55R6-JX65

Affected Products

Prefect