Argument Injection Flaw in PrefectHQ's GitRepository Pull Handler
CVE-2026-7725
Key Information:
Badges
What is CVE-2026-7725?
A vulnerability exists in PrefectHQ's product related to the GitRepository Pull Handler, specifically within the file src/prefect/runner/storage.py. The issue arises from improper handling of arguments, specifically the 'commit_sha' and 'directories' parameters, leading to potential argument injection. This can be exploited remotely, making it a significant security concern. Users are advised to upgrade to version 3.6.25.dev7 or higher, where the vulnerability is addressed through a patch identified as 6a9d9918716ce4ee0297b69f3046f7067ef1faae.
Affected Version(s)
prefect 3.6.25.dev6
prefect 3.6.25.dev7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
