๐Ÿ” CVE Alert

CVE-2026-72538

HIGH 8.8

PrefectHQ Prefect - Argument Injection

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone pull step branch field. The branch parameter is passed directly to git pull without sanitization, enabling injection of arbitrary git arguments. This represents a distinct code path from the incomplete fix applied for CVE-2026-5366 and allows command execution on the Prefect server.

CWE CWE-88
Vendor prefecthq
Product prefect
Published Aug 11, 2026
Last Updated Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for prefecthq prefect

Be the first to know when new high vulnerabilities affecting prefecthq prefect are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

PrefectHQ / Prefect
0 โ‰ค 3.8.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/PrefectHQ/prefect

Credits

Bobur Abdugafforov (Mahadsec)