Junglewise Threat Intelligence

CVE-2026-72538: PrefectHQ Prefect argument injection in git_clone pull step

CVE-2026-72538 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: PrefectHQ Prefect.

Executive brief

Prefect is a workflow orchestration framework that manages data pipelines and automation tasks. An authenticated user can inject arbitrary git arguments via the branch parameter in git operations, leading to remote code execution on the Prefect server. This could allow an attacker with valid credentials to execute malicious code and compromise the server or connected systems.

Technical details

An argument injection vulnerability exists in the git_clone pull step where the branch parameter is passed directly to git pull without sanitization. This allows authenticated attackers to inject arbitrary git arguments and achieve remote code execution on the Prefect server. The vulnerability is a distinct code path from the incomplete fix applied for CVE-2026-5366. Attack requires authentication but can lead to full server compromise through command execution.

Affected products

  • PrefectHQ Prefect through 3.8.2

Timeline

  • 2026-08-11: disclosed

References