PT-2026-64140 · Pypi · Sh

Publicado

2026-07-23

·

Atualizado

2026-07-23

CVSS v3.1

7.9

Alta

VetorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Impact

The uid option performed an incomplete privilege drop on Linux/Unix-like systems.
When sh was run from a process with elevated privileges, such as root, and a command was launched with uid=<unprivileged user>, the child process changed its UID and primary GID but did not reset its supplementary groups. As a result, the child process could retain the parent process’s supplementary groups, potentially including privileged groups such as root, docker, disk, shadow, or sudo.
This could allow a subprocess that was expected to run with reduced privileges to access files or resources available to the original process’s supplementary groups. Users are impacted if they rely on uid as a privilege boundary when launching commands from a privileged parent process.

Patches

Upgrade to version >= 2.2.4

Workarounds

Avoid using uid when the user represents a less-privileged user.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2026-3540

Produtos afetados

Sh