CVE-2023-6022High· 8.8▾ TwilightCross-Site Request Forgery vulnerability in Prefect
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.4%
Last analysed / modified upstream
An attacker is able to steal secrets and potentially gain remote code execution via CSRF using a self-hosted, open source Prefect API.
prefect >= 2.0.0, < 2.16.5Upgrade to a patched release:
prefect 2.16.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-7724Medium· 5.0Prefect SSRF Bypass via DNS Rebinding in validate_restricted_url
CVE-2026-7723High· 7.3Prefect Unauthenticated Event Injection via /api/events/in WebSocket
CVE-2026-3515High· 8.5Prefect has an Argument Injection issue
CVE-2026-7722Medium· 5.3Prefect Auth Bypass via endswith() Health Check Exemption
CVE-2026-7725Medium· 6.3Prefect Git Argument Injection in GitRepository Pull Steps
CVE-2026-3514High· 7.5Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'