CVE-2026-3515Patch

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated directly into a `git clone` command string without proper sanitization, and then parsed by `shlex.split()`. This enables injection of options such as `-c`, leading to potential Server-Side Request Forgery (SSRF), credential theft, or remote code execution (RCE). The vulnerability affects both the `aget_directory()` and `get_directory()` methods in `src/integrations/prefect-github/prefect_github/repository.py`. This issue does not affect the GitLab and BitBucket integrations, which use a safer list-based command construction approach.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-24); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-24: 1Mentions · 2026-06-07: 1Mentions · 2026-06-08: 1Mentions · 2026-06-12: 1Patch / Workaround · 2026-06-07: 1Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-06-12: 1Technical Details · 2026-05-24: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-12: 105-2406-0706-0806-12
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-241
Disclosure1
2026-06-071
Patch1
2026-06-081
General1
2026-06-121
Patch1
Full discourse4 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-3515 Prefect 3.6.18の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/06/cve-2026-3515-prefect-3618/ #IT #Security #cybersecurity

    Post summary

    The post offers a detailed explanation of CVE-2026-3515 affecting Prefect 3.6.18, covering its impact and mitigation steps, but does not provide a PoC, exploit code, or evidence of active exploitation.

    0001054
    209 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3515 A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line op… https://www.cve.org/CVERecord?id=CVE-2026-3515

    Post summary

    This post announces CVE-2026-3515, a command‑line injection flaw in Prefect’s prefect‑github integration (version 3.6.18) that allows attackers to execute arbitrary git commands.

    00010220
    57.5K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-3515 Prefect 3.6.18の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/06/cve-2026-3515-prefect-3618/ #IT #Security #cybersecurity

    Post summary

    The linked article explains the CVE‑2026‑3515 defect in Prefect 3.6.18, detailing its impact and providing patch or mitigation guidance.

    0000043
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-3515 Prefect 3.6.18の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/06/cve-2026-3515-prefect-3618/ #IT #Security #cybersecurity

    Post summary

    The article explains the CVE‑2026‑3515 vulnerability in Prefect 3.6.18 and summarizes its impact along with recommended countermeasures, likely covering vendor patches.

    0000029
    209 followersView on X

Explore more