Skip to content
PrefectGHSA-4hh5-2678-83fx

Cross-Site Request Forgery vulnerability in Prefect

High8.8CVE-2023-6022 · Published Nov 16, 2023 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
prefect
PyPI
>= 2.0.0, < 2.16.52.16.5
Details and references

An attacker is able to steal secrets and potentially gain remote code execution via CSRF using a self-hosted, open source Prefect API.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-352
Also known as
CVE-2023-6022, PYSEC-2026-1799

More Prefect advisories

All Prefect
DateAdvisory
Mar 202025Prefect CORS (Cross-Origin Resource Sharing) misconfiguration
CVE-2024-8183High7.6fixed in 2.20.17, 3.0.3
May 4Prefect Auth Bypass via endswith() Health Check Exemption
CVE-2026-7722Medium5.3fixed in 3.6.22
May 4Prefect Unauthenticated Event Injection via /api/events/in WebSocket
CVE-2026-7723Medium7.3fixed in 3.6.14
May 4Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url
CVE-2026-7724Low5.0fixed in 3.6.28.dev2
May 4Prefect Git Argument Injection in GitRepository Pull Steps
CVE-2026-7725Low6.3fixed in 3.6.25.dev7
May 26Prefect has an Argument Injection issue
CVE-2026-3515High8.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.