PrefectGHSA-4hh5-2678-83fx
Cross-Site Request Forgery vulnerability in Prefect
High8.8CVE-2023-6022 · Published Nov 16, 2023 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| prefect PyPI | >= 2.0.0, < 2.16.5 | 2.16.5 |
Details and references
An attacker is able to steal secrets and potentially gain remote code execution via CSRF using a self-hosted, open source Prefect API.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-352
- Also known as
- CVE-2023-6022, PYSEC-2026-1799
More Prefect advisories
All Prefect| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | Prefect CORS (Cross-Origin Resource Sharing) misconfiguration CVE-2024-8183High7.6fixed in 2.20.17, 3.0.3 | High7.6 | 2.20.17, 3.0.3 |
| May 4 | Prefect Auth Bypass via endswith() Health Check Exemption CVE-2026-7722Medium5.3fixed in 3.6.22 | Medium5.3 | 3.6.22 |
| May 4 | Prefect Unauthenticated Event Injection via /api/events/in WebSocket CVE-2026-7723Medium7.3fixed in 3.6.14 | Medium7.3 | 3.6.14 |
| May 4 | Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url CVE-2026-7724Low5.0fixed in 3.6.28.dev2 | Low5.0 | 3.6.28.dev2 |
| May 4 | Prefect Git Argument Injection in GitRepository Pull Steps CVE-2026-7725Low6.3fixed in 3.6.25.dev7 | Low6.3 | 3.6.25.dev7 |
| May 26 | Prefect has an Argument Injection issue CVE-2026-3515High8.5no fix yet | High8.5 | No fix yet |