{"id":"GHSA-hc8w-h2mf-hp59","summary":"PowerShell Command Injection in Podman HyperV Machine","details":"## Summary\n\nA command injection vulnerability exists in Podman's HyperV machine backend. The VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing `$()` subexpression injection.\n\n## Affected Code\n\n**File**: `pkg/machine/hyperv/stubber.go:647`\n\n```go\nresize := exec.Command(\"powershell\", []string{\n    \"-command\",\n    fmt.Sprintf(\"Resize-VHD \\\"%s\\\" %d\", imagePath.GetPath(), newSize.ToBytes()),\n}...)\n```\n\n\n\n## Root Cause\n\nPowerShell evaluates `$()` subexpressions inside double-quoted strings before executing the outer command. The `fmt.Sprintf` call places the user-controlled image path directly into double quotes without escaping or sanitization.\n\n## Impact\n\nAn attacker who can control the VM image path (through a crafted machine name or image directory) can execute arbitrary PowerShell commands with the privileges of the Podman process on the Windows host. On typical Windows installations, this means SYSTEM-level code execution.\n\n\n## Patch\n\nhttps://github.com/containers/podman/commit/571c842bd357ee626019ea97d030fb772fc654ed\n\nThe affected code is only used on Windows, all other operating systems are not affected by this and can thus ignore the CVE patch.\n\n## Credit\n\nWe like to thank Sang-Hoon Choi (@KoreaSecurity) for reporting this issue to us.","aliases":["CVE-2026-33414","GO-2026-5421"],"modified":"2026-07-17T21:08:47.121213180Z","published":"2026-04-14T22:30:24Z","database_specific":{"nvd_published_at":"2026-04-14T23:16:27Z","cwe_ids":["CWE-78"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-04-14T22:30:24Z"},"references":[{"type":"WEB","url":"https://github.com/containers/podman/security/advisories/GHSA-hc8w-h2mf-hp59"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33414"},{"type":"WEB","url":"https://github.com/containers/podman/commit/571c842bd357ee626019ea97d030fb772fc654ed"},{"type":"PACKAGE","url":"https://github.com/containers/podman"}],"affected":[{"package":{"name":"github.com/containers/podman/v4","ecosystem":"Go","purl":"pkg:golang/github.com/containers/podman/v4"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.8.0"},{"last_affected":"4.9.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-hc8w-h2mf-hp59/GHSA-hc8w-h2mf-hp59.json"}},{"package":{"name":"github.com/containers/podman/v5","ecosystem":"Go","purl":"pkg:golang/github.com/containers/podman/v5"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.8.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 5.8.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-hc8w-h2mf-hp59/GHSA-hc8w-h2mf-hp59.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"}]}