PT-2026-32953 · Podman · Podman

Koreasecurity

·

Published

2026-04-14

·

Updated

2026-05-06

·

CVE-2026-33414

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Podman versions 4.8.0 through 5.8.1
Description A command injection issue exists in the HyperV machine backend within the file pkg/machine/hyperv/stubber.go. The VM image path is inserted into a PowerShell double-quoted string without sanitization, which allows for $() subexpression injection. Since PowerShell evaluates subexpressions inside double-quoted strings before executing the outer command, an attacker who controls the VM image path via a crafted machine name or image directory can execute arbitrary PowerShell commands. This occurs with the privileges of the Podman process, which on typical Windows installations results in SYSTEM-level code execution. This issue exclusively affects Windows.
Recommendations Update to version 5.8.2.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-33414
GHSA-HC8W-H2MF-HP59
OPENSUSE-SU-2026:10706-1
RHSA-2026:8211

Affected Products

Podman