CVE-2026-33310: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-33310 is a command injection vulnerability in the Python Intake data catalog package, classified as "Command Injection via shell() Expansion in Parameter Defaults." Prior to version 2.0.9, Intake automatically expands shell(<command>) syntax embedded in parameter default values during catalog YAML parsing, allowing arbitrary OS commands to execute on the host system when a user loads a malicious catalog file. The vulnerability affects all Intake versions prior to 2.0.9 and was disclosed on March 18, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).

Technical details

The root cause lies in Intake's expand_defaults() function and related parameter parsing mechanisms, which process shell() expressions in catalog YAML parameter defaults without sanitization or user opt-in controls (CWE-78: OS Command Injection; CWE-94: Code Injection). When a catalog source is accessed via intake.open_catalog(), the library resolves parameter default values and passes any shell(<command>) expression to a subprocess for execution — before the user explicitly interacts with the dataset. The attack requires no privileges from the attacker; it only requires that a victim user loads a crafted YAML catalog file, making it a social-engineering-dependent remote code execution vector. A public PoC is included in the GitHub Security Advisory, consisting of a malicious exploit.yaml with default: "shell(touch /tmp/intake_rce_test)" and a reproduce.py script that confirms command execution (GitHub Advisory).

Impact

Successful exploitation results in arbitrary OS command execution on the victim's host system with the privileges of the Intake process, yielding full confidentiality, integrity, and availability impact. An attacker can read sensitive files, modify or delete data, install malware, establish persistence, or pivot to other systems accessible from the compromised host. The attack surface is broad because malicious catalogs can be distributed through Git repositories, shared datasets, URLs, or data science workflow pipelines, potentially affecting any data scientist or analyst using Intake (GitHub Advisory).

Exploitability

A working proof-of-concept exploit (both the malicious YAML payload and a Python reproduction script) is publicly available in the GitHub Security Advisory and has also been published in a separate repository (github.com/redyank/CVE-2026-33310). As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.053% (0.000530), indicating a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Qualys scanner (detection ID 5009527) has added detection support (GitHub Advisory).

Exploitation steps

  1. Craft malicious catalog YAML: Create a file (e.g., exploit.yaml) with a parameter default containing a shell() expression:
metadata:
  version: 1
sources:
  rce_test:
    driver: csv
    description: "Testing shell expansion in parameters"
    args:
      urlpath: "{{ cmd_exec }}"
    parameters:
      cmd_exec:
        display_name: "Test Parameter"
        type: str
        default: "shell(touch /tmp/intake_rce_test)"
  1. Distribute the catalog: Host or share the malicious YAML via a Git repository, data-sharing platform, URL, or embed it in a data science workflow that the target user is likely to load.
  2. Victim loads the catalog: The victim runs intake.open_catalog('exploit.yaml') or accesses a source entry (e.g., cat['rce_test']), triggering catalog parsing.
  3. Automatic shell expansion: During parsing, Intake's expand_defaults() function processes the shell(touch /tmp/intake_rce_test) default value and spawns a subprocess to execute the embedded command.
  4. Command executes: The OS command runs with the privileges of the victim's Intake process — the attacker can substitute any payload (reverse shell, data exfiltration, persistence mechanism) in place of the touch command (GitHub Advisory).

Indicators of compromise

  • File System: Unexpected files created in /tmp/ or other writable directories (e.g., /tmp/intake_rce_test from the PoC); new scripts, cron jobs, or SSH keys added by the Intake process user.
  • Process: Unusual child processes spawned by the Python/Intake process (e.g., bash, sh, curl, wget, python, nc) visible in process trees; subprocess calls originating from intake or python executables.
  • Logs: System audit logs (e.g., auditd) showing subprocess execution initiated by a Python process loading a YAML file; shell history entries referencing intake.open_catalog() followed by unexpected system activity.
  • Network: Outbound connections to unknown external IPs or C2 infrastructure initiated by the Python/Intake process shortly after catalog loading (GitHub Advisory).

Mitigation and workarounds

Upgrade Intake to version 2.0.9 or later, which mitigates the issue by setting getshell=False by default everywhere, disabling automatic shell() expansion during catalog parsing. As interim workarounds: avoid loading catalog YAML files from untrusted or unverified sources; implement controls to restrict which catalogs users are permitted to load; and audit existing catalog files for shell() expressions in parameter defaults. The fix commit is available at github.com/intake/intake/commit/d0c0b6b57c1cb3f73880655ded4a9b0e18e1fd1b (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher redyank, who is credited in the GitHub Security Advisory. Coverage appeared on The Hacker Wire and security aggregator sites (infinitsec.net, cvefeed.io) shortly after disclosure. The advisory was noted on Bluesky by CVE tracking accounts. OpenSUSE issued a security announcement referencing the vulnerability as part of a broader package update advisory (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management