Prefect has an Argument Injection issue
High8.5CVE-2026-3515 · Published May 26, 2026 · updated Sep 10, 2026
A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated directly into a `git clone` command string without proper sanitization, and then parsed by `shlex.split()`. This enables injection of options such as `-c`, leading to potential Server-Side Request Forgery (SSRF), credential theft, or remote code execution (RCE). The vulnerability affects both the `aget_directory()` and `get_directory()` methods in `src/integrations/prefect-github/prefect_github/repository.py`. This issue does not affect the GitLab and BitBucket integrations, which use a safer list-based command construction approach.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| prefect PyPI | <= 3.6.18 | No fix yet |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-88
- Also known as
- CVE-2026-3515, PYSEC-2026-2957
More Prefect advisories
All Prefect| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 2 | Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready' | High7.5 | 3.6.22.dev7 |
| May 4 | Prefect Git Argument Injection in GitRepository Pull Steps | Low6.3 | 3.6.25.dev7 |
| May 4 | Prefect Auth Bypass via endswith() Health Check Exemption | Medium5.3 | 3.6.22 |
| May 4 | Prefect Unauthenticated Event Injection via /api/events/in WebSocket | Medium7.3 | 3.6.14 |
| May 4 | Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url | Low5.0 | 3.6.28.dev2 |
| Mar 202025 | Prefect CORS (Cross-Origin Resource Sharing) misconfiguration | High7.6 | 2.20.17+1 more |