PT-2026-95513 · Pypi · Anyio

CVE-2026-63349

·

Published

2026-09-18

·

Updated

2026-10-01

CVSS v4.0

7.0

High

VectorAV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions AnyIO versions 4.14.0 through 4.14.1
Description AnyIO is a high-level asynchronous concurrency and networking framework. In POSIX applications, the anyio.open process() function incorrectly forwards the group variable to the backend instead of the extra groups variable. This occurs when extra groups is not None, causing the framework to assign kwargs["extra groups"] = group. Consequently, callers attempting to clear inherited supplementary groups by supplying extra groups=[] may launch a child process that retains the parent process groups, which undermines privilege-dropping boundaries. Additionally, if the group parameter is supplied, an integer value is passed where an iterable of supplementary groups is expected, which can result in a TypeError and cause the process launch to fail.
Recommendations Update to version 4.14.2.

Exploit

Fix

Incorrect Privilege Assignment

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63349
ECHO-5D39-DA23-651E
GHSA-3W57-8XMC-8V26
PYSEC-2026-4023

Affected Products

Anyio