CVE-2026-5366 is a critical argument injection vulnerability in Prefect 3.6.23 affecting the GitRepository storage class. User-controlled input supplied through the commit_sha parameter is passed to git commands without adequate validation and without a -- argument separator, allowing attacker-supplied values to be interpreted as git flags rather than inert revision input. The directories parameter is similarly exposed during sparse-checkout operations, creating an additional injection path. By injecting arbitrary git options, including options that cause git to invoke external programs, an attacker can achieve remote code execution on Prefect worker machines. The issue is especially dangerous in shared work pools and multi-tenant deployments because it allows a user with deployment creation permissions to cross trust boundaries and execute commands in the worker execution environment.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept for CVE-2026-5366 affecting Prefect GitRepository handling in version 3.6.23. It contains three files: a detailed README, a Python exploit driver (poc.py), and a Bash helper (run_offline.sh) that creates a local bare git repository and runs the PoC without network access. The main exploit logic is in poc.py. It imports prefect.runner.storage.GitRepository and tests two attacker-controlled parameters: commit_sha and directories. The exploit relies on Prefect passing commit_sha directly into git fetch/checkout argument lists without validation or a -- separator. By supplying a value beginning with --upload-pack=/bin/sh -c ..., git interprets the attacker input as an option and executes /bin/sh locally when using file:// or SSH transports. The payload writes marker files in the temp directory to prove code execution. The script intentionally cleans clone destinations to force Prefect down the _clone_repo path, catches expected git errors after payload execution, and prints a summary of which vector succeeded. The directories vector is also tested, because Prefect passes directories into git sparse-checkout set without a -- separator. However, the repository correctly notes and demonstrates that this is only argument injection, not RCE with the provided payload, because sparse-checkout does not support --upload-pack. run_offline.sh is an operational wrapper that builds a temporary local git repo, clones it as a bare repo, exports POC_TARGET_REPO as a file:// URL, and runs poc.py from a throwaway directory. This makes the exploit reliable and self-contained, avoiding dependence on GitHub or external connectivity. Overall, this is a real exploit PoC rather than a detector. It is not framework-based. Its primary capability is local command execution on a vulnerable Prefect worker through malicious GitRepository.commit_sha input, with marker-file side effects used as proof.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously addressed related vulnerability referenced as having an incomplete fix, with CVE-2026-72538 affecting a distinct code path.
A critical remote code execution vulnerability in Prefect's GitRepository storage class caused by improper handling of user-controlled git arguments, allowing arbitrary command execution on worker machines.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.