PT-2026-70113 · Prefecthq+1 · Prefect
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PrefectHQ Prefect versions prior to 3.8.3
Description
Authenticated users can achieve remote code execution on the Prefect server through an argument injection flaw. The issue occurs because the
branch parameter in the git clone pull step is passed directly to the git pull command without proper sanitization, allowing the injection of arbitrary git arguments.Recommendations
Update PrefectHQ Prefect to version 3.8.3 or later.
Avoid using the
branch parameter in the git clone pull step until the update is applied.Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prefect