{"id":"GHSA-37g4-qqqv-7m99","summary":"Intake has a Command Injection via shell() Expansion in Parameter Defaults","details":"### Summary\nThe shell() syntax within parameter default values appears to be automatically expanded during the catalog parsing process.\nIf a catalog contains a parameter default such as shell(\u003ccommand\u003e), the command may be executed when the catalog source is accessed.\nThis means that if a user loads a malicious catalog YAML, embedded commands could execute on the host system.\nThis behavior could potentially be classified as OS Command Injection / Unsafe Shell Expansion.\n\n### Details\nThe issue appears to originate from how parameter default values are expanded when a catalog source is accessed.\n\nDuring catalog loading and source access:\n\nIntake resolves parameter default values\nThe function responsible for expanding defaults processes the shell() syntax\nThe shell expression triggers a subprocess execution\nBecause this occurs during catalog evaluation, the command may execute before the user explicitly interacts with the dataset itself.\n\nAffected logic appears to involve:\n```\nexpand_defaults()\n```\nand related parameter parsing mechanisms.\n\n\n### PoC\nexploit.yaml\n```\nmetadata:\n  version: 1\nsources:\n  rce_test:\n    driver: csv\n    description: \"Testing shell expansion in parameters\"\n    args:\n      urlpath: \"{{ cmd_exec }}\"\n    parameters:\n      cmd_exec:\n        display_name: \"Test Parameter\"\n        type: str\n        default: \"shell(touch /tmp/intake_rce_test)\"\n```\n\nreproduce.py\n```\nimport intake\nimport os\n\nPROOF_FILE = \"/tmp/intake_rce_test\"\n\nif os.path.exists(PROOF_FILE):\n    os.remove(PROOF_FILE)\n\nprint(f\"[*] Proof file exists before: {os.path.exists(PROOF_FILE)}\")\n\ntry:\n    cat = intake.open_catalog(\"exploit.yaml\")\n\n    print(\"Accessing source...\")\n    _ = cat[\"rce_test\"]\n\nexcept Exception as e:\n    print(f\" Error during execution: {e}\")\n\nif os.path.exists(PROOF_FILE):\n    print(f\" Command execution confirmed, Found: {PROOF_FILE}\")\nelse:\n    print(\"Command execution did not occur.\")\n```\n### Attack Scenario\nA potential attack scenario could be:\n\n1. An attacker publishes a malicious Intake catalog YAML file\n2. The victim downloads or loads the catalog\n3. The victim accesses a source entry in the catalog\n4. Parameter defaults are expanded\n5. The shell() expression triggers execution of the embedded command\n\n### Impact\n\nIf this behavior is confirmed to be unintended, an attacker could distribute a malicious catalog file via:\n\n- Git repositories\n- shared datasets\n- URLs\n- data science workflows\n- Any user loading the catalog could unknowingly execute commands with their local user privileges.\n\n### Recommendation\nPossible mitigations could include:\n\n- disabling shell() expansion by default\n- requiring an explicit opt-in flag (e.g., allow_shell=True)\n- restricting shell execution for catalogs loaded from untrusted sources\nPlease let me know if additional information or testing is needed.\nI'm happy to assist with further analysis or validation.","aliases":["CVE-2026-33310","PYSEC-2026-2185"],"modified":"2026-07-13T07:26:36.151264920Z","published":"2026-03-19T17:46:54Z","database_specific":{"nvd_published_at":"2026-03-24T14:16:30Z","cwe_ids":["CWE-78","CWE-94"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-19T17:46:54Z"},"references":[{"type":"WEB","url":"https://github.com/intake/intake/security/advisories/GHSA-37g4-qqqv-7m99"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33310"},{"type":"WEB","url":"https://github.com/intake/intake/commit/d0c0b6b57c1cb3f73880655ded4a9b0e18e1fd1b"},{"type":"PACKAGE","url":"https://github.com/intake/intake"}],"affected":[{"package":{"name":"intake","ecosystem":"PyPI","purl":"pkg:pypi/intake"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.0.9"}]}],"versions":["0.1.2","0.1.3","0.2.3","0.2.8","0.2.9","0.3.0","0.3.1","0.4.0","0.4.1","0.4.2","0.4.3","0.4.4","0.5.0","0.5.1","0.5.2","0.5.3","0.5.4","0.5.5","0.6.0","0.6.1","0.6.2","0.6.3","0.6.4","0.6.5","0.6.6","0.6.7","0.6.8","0.7.0","2.0.0","2.0.0a1","2.0.0a2","2.0.1","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-37g4-qqqv-7m99/GHSA-37g4-qqqv-7m99.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}