PT-2026-105784 · Pypi · Anyio
Publicado
2026-10-01
·
Atualizado
2026-10-01
CVSS v4.0
7.0
Alta
| Vetor | AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
AnyIO 4.14.0 accepts the POSIX extra groups argument on anyio.run process() and anyio.open process(), but open process() forwards the wrong variable to the backend: when extra groups is not None, it assigns kwargs["extra groups"] = group instead of extra groups. As a result, callers cannot reliably clear or set supplementary groups for child processes. In a disposable Linux container, Python's subprocess.run(..., extra groups=[]) clears a synthetic parent supplementary group list, while anyio.run process(..., extra groups=[]) preserves the parent groups. If group is also supplied, AnyIO passes an integer as extra groups and the call fails with TypeError. This is a POSIX privilege-dropping correctness issue for applications that rely on AnyIO subprocess helpers to launch less-privileged child processes.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Anyio