← Back

CVE-2026-33310

nvd nist
Published: Mar 24, 2026Modified: Mar 25, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: security-advisories@github.com (Secondary)

Description

Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() syntax within parameter default values appears to be automatically expanded during the catalog parsing process. If a catalog contains a parameter default such as shell(<command>), the command may be executed when the catalog source is accessed. This means that if a user loads a malicious catalog YAML, embedded commands could execute on the host system. Version 2.0.9 mitigates the issue by making getshell False by default everywhere.

Affected (1)

Products: Intake: Intake
1 product
Intake
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.0.9

References (2)

Source: security-advisories@github.com
ExploitVendor Advisory

Timeline

No history available yet.