PT-2026-95513 · Pypi · Anyio
CVE-2026-63349
·
Published
2026-09-18
·
Updated
2026-10-01
CVSS v4.0
7.0
High
| Vector | AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
AnyIO versions 4.14.0 through 4.14.1
Description
AnyIO is a high-level asynchronous concurrency and networking framework. In POSIX applications, the
anyio.open process() function incorrectly forwards the group variable to the backend instead of the extra groups variable. This occurs when extra groups is not None, causing the framework to assign kwargs["extra groups"] = group. Consequently, callers attempting to clear inherited supplementary groups by supplying extra groups=[] may launch a child process that retains the parent process groups, which undermines privilege-dropping boundaries. Additionally, if the group parameter is supplied, an integer value is passed where an iterable of supplementary groups is expected, which can result in a TypeError and cause the process launch to fail.Recommendations
Update to version 4.14.2.
Exploit
Fix
Incorrect Privilege Assignment
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anyio