CVE-2026-33310Disclosure(intake / intake)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch intake intake systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() syntax within parameter default values appears to be automatically expanded during the catalog parsing process. If a catalog contains a parameter default such as shell(<command>), the command may be executed when the catalog source is accessed. This means that if a user loads a malicious catalog YAML, embedded commands could execute on the host system. Version 2.0.9 mitigates the issue by making getshell False by default everywhere.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • intake

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
intake

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-24: 3Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-24: 203-24
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-33310 Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() syntax within parameter default values appears to … https://www.cve.org/CVERecord?id=CVE-2026-33310

    Post summary

    The post merely announces the existence of CVE-2026-33310 with an incomplete description and a link to the CVE record, lacking specific technical or exploit details.

    00001106
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33310 - High Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() syntax within parameter default values appears to be automatically expanded... https://www.thehackerwire.com/vulnerability/CVE-2026-33310/ https://t.co/QEMgM4cCPO

    Post summary

    The post announces the high‑severity CVE‑2026‑33310 in Intake, noting that shell() syntax within default parameters is automatically expanded before version 2.0.9, potentially allowing malicious code execution.

    0000047
    145 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33310: HIGH] Intake 2.0.9 release addresses security vulnerability enabling shell command execution via parameter default values in catalog source, enhancing cyber protection.#cve,CVE-2026-33310,#cybersecurity https://cvefind.com/CVE-2026-33310

    Post summary

    The Intake 2.0.9 release includes a patch for CVE-2026-33310, fixing a shell command execution vulnerability that exploited parameter default values.

    0000032
    606 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appintakeintake---

Explore more