Intelligence View
CVE-2026-7725 | PrefectHQ prefect up to 3.6.25.dev6 GitRepository Pull storage.py commit_sha/directories argument injection
A vulnerability categorized as critical has been discovered in PrefectHQ prefect up to 3.6.25.dev6. Affected by this issue is some unknown functionality of the file src/prefect/runner/storage.py of the component GitRepository Pull Handler.…
This vulnerability is known as CVE-2026-7725. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is advisable to upgrade the affected component.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
2. Cyber Threat Intelligence & Forensik
3. Compliance, SLA & Vendor Adherence
Hersteller-Sicherheitsmeldungen & Patch-Status
Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Web Referencevuldb.com
-
Web Referencegist.github.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com