CVE-2026-3515 | prefecthq prefect up to 3.6.18 repository.py shlex.split reference argument injection
A vulnerability identified as critical has been detected in prefecthq prefect up to 3.6.18. This affects the function shlex.split of the file src/integrations/prefect-github/prefect_github/repository.py. Performing a manipulation of the argument reference results in argument injection.
This vulnerability is reported as CVE-2026-3515. The attack is possible to be carried out remotely. No exploit exists.