boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-5366CRITICAL
prefecthq prefecthq/prefect — Git Argument Injection in prefecthq/prefect
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  C  H  H  H    9.9   .0087   56.1     —
AFFECTED
  Product            Versions       Fixed
  prefecthq/prefect  unspecified –  —
TIMELINE
  Apr 1   Reserved by @huntr_ai
  Jun 20  EXPLOIT PUBLISHED — CVE-2026-5366 (prefecthq/prefect). Public exploit reference added.
  Jun 20  Published (CNA: @huntr_ai)
CWE-94 · CNA: @huntr_ai · CVSS v3.0 · 1 reference · NVD status: Analyzed

Description

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to git commands, lacks validation and does not include a `--` separator to distinguish user input from git flags. This allows attackers to inject arbitrary git flags, such as `--upload-pack`, enabling execution of external programs. Additionally, the `directories` parameter can be exploited to inject git flags during sparse-checkout operations. These vulnerabilities allow any user with deployment creation permissions to execute arbitrary commands on worker machines, compromising shared work pools in multi-tenant environments.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
April 1, 2026ReservedReserved by @huntr_ai
June 20, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-5366 (prefecthq/prefect). Public exploit reference added.
June 20, 2026PublishedPublished (CNA: @huntr_ai)

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
prefecthqprefecthq/prefectunspecified

Weaknesses

CWE-94

References (1)

Related

Authoritative record: CVE-2026-5366 at cve.org

Vendors: prefecthq

Weaknesses: CWE-94

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-5366 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.