{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-5366", "assignerOrgId": "c09c270a-b464-47c1-9133-acb35b22c19a", "state": "PUBLISHED", "assignerShortName": "@huntr_ai", "dateReserved": "2026-04-01T18:18:27.682Z", "datePublished": "2026-06-20T16:43:37.345Z", "dateUpdated": "2026-06-22T17:25:02.152Z" }, "containers": { "cna": { "title": "Git Argument Injection in prefecthq/prefect", "providerMetadata": { "orgId": "c09c270a-b464-47c1-9133-acb35b22c19a", "shortName": "@huntr_ai", "dateUpdated": "2026-06-20T16:43:37.345Z" }, "descriptions": [ { "lang": "en", "value": "Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to git commands, lacks validation and does not include a `--` separator to distinguish user input from git flags. This allows attackers to inject arbitrary git flags, such as `--upload-pack`, enabling execution of external programs. Additionally, the `directories` parameter can be exploited to inject git flags during sparse-checkout operations. These vulnerabilities allow any user with deployment creation permissions to execute arbitrary commands on worker machines, compromising shared work pools in multi-tenant environments." } ], "affected": [ { "vendor": "prefecthq", "product": "prefecthq/prefect", "versions": [ { "version": "unspecified", "status": "affected", "versionType": "custom", "lessThanOrEqual": "latest" } ] } ], "references": [ { "url": "https://huntr.com/bounties/e2e88a0f-a8f6-49c9-94c5-e98dc385f07a" } ], "metrics": [ { "cvssV3_0": { "version": "3.0", "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "CHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", "baseScore": 9.9, "baseSeverity": "CRITICAL" } } ], "problemTypes": [ { "descriptions": [ { "type": "CWE", "lang": "en", "description": "CWE-94 Improper Control of Generation of Code", "cweId": "CWE-94" } ] } ], "source": { "advisory": "e2e88a0f-a8f6-49c9-94c5-e98dc385f07a", "discovery": "EXTERNAL" } }, "adp": [ { "references": [ { "url": "https://huntr.com/bounties/e2e88a0f-a8f6-49c9-94c5-e98dc385f07a", "tags": [ "exploit" ] } ], "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-06-22T17:24:58.249220Z", "id": "CVE-2026-5366", "options": [ { "Exploitation": "poc" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-06-22T17:25:02.152Z" } } ] } }