
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33310 is a command injection vulnerability in the Python Intake data catalog package, classified as "Command Injection via shell() Expansion in Parameter Defaults." Prior to version 2.0.9, Intake automatically expands shell(<command>) syntax embedded in parameter default values during catalog YAML parsing, allowing arbitrary OS commands to execute on the host system when a user loads a malicious catalog file. The vulnerability affects all Intake versions prior to 2.0.9 and was disclosed on March 18, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).
The root cause lies in Intake's expand_defaults() function and related parameter parsing mechanisms, which process shell() expressions in catalog YAML parameter defaults without sanitization or user opt-in controls (CWE-78: OS Command Injection; CWE-94: Code Injection). When a catalog source is accessed via intake.open_catalog(), the library resolves parameter default values and passes any shell(<command>) expression to a subprocess for execution — before the user explicitly interacts with the dataset. The attack requires no privileges from the attacker; it only requires that a victim user loads a crafted YAML catalog file, making it a social-engineering-dependent remote code execution vector. A public PoC is included in the GitHub Security Advisory, consisting of a malicious exploit.yaml with default: "shell(touch /tmp/intake_rce_test)" and a reproduce.py script that confirms command execution (GitHub Advisory).
Successful exploitation results in arbitrary OS command execution on the victim's host system with the privileges of the Intake process, yielding full confidentiality, integrity, and availability impact. An attacker can read sensitive files, modify or delete data, install malware, establish persistence, or pivot to other systems accessible from the compromised host. The attack surface is broad because malicious catalogs can be distributed through Git repositories, shared datasets, URLs, or data science workflow pipelines, potentially affecting any data scientist or analyst using Intake (GitHub Advisory).
A working proof-of-concept exploit (both the malicious YAML payload and a Python reproduction script) is publicly available in the GitHub Security Advisory and has also been published in a separate repository (github.com/redyank/CVE-2026-33310). As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.053% (0.000530), indicating a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Qualys scanner (detection ID 5009527) has added detection support (GitHub Advisory).
exploit.yaml) with a parameter default containing a shell() expression:metadata:
version: 1
sources:
rce_test:
driver: csv
description: "Testing shell expansion in parameters"
args:
urlpath: "{{ cmd_exec }}"
parameters:
cmd_exec:
display_name: "Test Parameter"
type: str
default: "shell(touch /tmp/intake_rce_test)"intake.open_catalog('exploit.yaml') or accesses a source entry (e.g., cat['rce_test']), triggering catalog parsing.expand_defaults() function processes the shell(touch /tmp/intake_rce_test) default value and spawns a subprocess to execute the embedded command.touch command (GitHub Advisory)./tmp/ or other writable directories (e.g., /tmp/intake_rce_test from the PoC); new scripts, cron jobs, or SSH keys added by the Intake process user.bash, sh, curl, wget, python, nc) visible in process trees; subprocess calls originating from intake or python executables.auditd) showing subprocess execution initiated by a Python process loading a YAML file; shell history entries referencing intake.open_catalog() followed by unexpected system activity.Upgrade Intake to version 2.0.9 or later, which mitigates the issue by setting getshell=False by default everywhere, disabling automatic shell() expansion during catalog parsing. As interim workarounds: avoid loading catalog YAML files from untrusted or unverified sources; implement controls to restrict which catalogs users are permitted to load; and audit existing catalog files for shell() expressions in parameter defaults. The fix commit is available at github.com/intake/intake/commit/d0c0b6b57c1cb3f73880655ded4a9b0e18e1fd1b (GitHub Advisory).
The vulnerability was reported by researcher redyank, who is credited in the GitHub Security Advisory. Coverage appeared on The Hacker Wire and security aggregator sites (infinitsec.net, cvefeed.io) shortly after disclosure. The advisory was noted on Bluesky by CVE tracking accounts. OpenSUSE issued a security announcement referencing the vulnerability as part of a broader package update advisory (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."