PT-2026-105784 · Pypi · Anyio

Publicado

2026-10-01

·

Atualizado

2026-10-01

CVSS v4.0

7.0

Alta

VetorAV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
AnyIO 4.14.0 accepts the POSIX extra groups argument on anyio.run process() and anyio.open process(), but open process() forwards the wrong variable to the backend: when extra groups is not None, it assigns kwargs["extra groups"] = group instead of extra groups. As a result, callers cannot reliably clear or set supplementary groups for child processes. In a disposable Linux container, Python's subprocess.run(..., extra groups=[]) clears a synthetic parent supplementary group list, while anyio.run process(..., extra groups=[]) preserves the parent groups. If group is also supplied, AnyIO passes an integer as extra groups and the call fails with TypeError. This is a POSIX privilege-dropping correctness issue for applications that rely on AnyIO subprocess helpers to launch less-privileged child processes.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2026-4023

Produtos afetados

Anyio