
🚨 CRITICAL - Prefect GitRepository git-flag injection leads to RCE (CVE-2026-5366) Prefect 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the GitRepository storage class. By injecting arbitrary git flags via the commit_sha or directories parameters, an attacker can coerce git operations into executing external programs. Any user with deployment creation permissions can exploit this to run commands on worker machines, turning a workflow deployment into a foothold. Impact is severe in shared or multi-tenant work pools, where a single compromised deployment can lead to cross-tenant compromise and full worker takeover. 👉 Affected: prefect 3.6.23 | Upgrade to No fix yet - treat as suspicious
Post summary
A critical RCE vulnerability (CVE‑2026‑5366) affects Prefect 3.6.23 via git flag injection; the text provides technical details but no PoC, exploit code, patch, or evidence of active exploitation.


