Bounties
Partners
Community
Info
prefecthq / prefect
Project repository
Prefect is a workflow orchestration framework for building resilient data pipelines in Python.
Submit a report
FIRST INTERACTION
WITHIN
14 DAYS
REVIEW
WITHIN
15 DAYS
FIX
WITHIN
86 DAYS
Missing Input Validation in Work Pool Storage Configuration Allows Arbitrary Mod...
Apr 20th 2026
ar03
•
informative
High
`LocalFileSystem` basepath enforcement is bypassable for reads, writes, and dire...
Apr 20th 2026
gunp1a
•
informative
Critical
`prefect.deployments.steps.git_clone` allows path traversal through `clone_direc...
Apr 20th 2026
gunp1a
•
informative
High
Unauthenticated secret exfiltration via include_secrets parameter + SSRF via web...
Apr 20th 2026
snakeyworm
•
informative
None
Unauthenticated secret exfiltration via include_secrets parameter + SSRF via web...
Apr 20th 2026
snakeyworm
•
informative
None
Unauthenticated RCE on Workers via Malicious Pull Steps in Deployment API
Apr 1st 2026
csaw-admin
•
not applicable
RCE via PREFECT_LOGGING_SETTINGS_PATH environment variable (dictConfig factory i...
Apr 1st 2026
wernerina
•
not applicable
CORS Wildcard + Default No Authentication → Workflow Data Theft + Deletion in Pr...
Mar 11th 2026
zuck3-r
•
informative
High
Unsafe cloudpickle deserialization in Prefect task runners and bundle deserializ...
Jun 5th 2026
etwithin
•
None
None
Unsafe deserialization via cloudpickle in Prefect flow and task serialization
Mar 9th 2026
etwithin
•
informative
High
Authentication Bypass via endswith() Health Check Exemption Allows Unauthenticat...
Jun 2nd 2026
galanzi2580-wq
•
High
High
•
CVE-2026-3514
CVE-2026-3514
Git Argument Injection via Reference Field in GitHubRepository Block
May 24th 2026
optimus-fulcria
•
High
High
•
CVE-2026-3515
CVE-2026-3515
CORS misconfiguration leads to data leak
Nov 19th 2024
srivallikusumba
•
High
•
$300
High
•
$300
•
CVE-2024-8183
CVE-2024-8183
Code injection
Jun 10th 2024
h2oa
•
informative
Critical
•
CVE-2024-4387
CVE-2024-4387
/api/logs endpoint has no upper limit on data input
Feb 16th 2024
mik0w
•
not applicable
Can use csrf to steal/modify block content, artifact content, variables possibly...
Nov 16th 2023
jbonnett
•
High
•
$15680
High
•
$15680
•
CVE-2023-6022
CVE-2023-6022
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0