AnyIO 4.14.0–4.14.1 Flaw Lets Subprocesses Retain Elevated Group Permissions
A high-severity vulnerability tracked as CVE-2026-63349 has been disclosed in AnyIO versions 4.14.0 and 4.14.1, a popular Python asynchronous framework. A variable assignment typo in the subprocess module causes subprocesses on POSIX systems to inherit the parent process's supplementary group permissions instead of dropping them as intended. This bypass, rated 7.0 on the CVSS v4.0 scale, could allow subprocesses to retain sensitive group memberships such as 'docker' or 'shadow', undermining privilege-separation security controls. The flaw is classified under CWE-266 and CWE-269 and currently has a proof-of-concept exploit available, though it has not been listed in the Known Exploited Vulnerabilities catalogue. Developers are advised to upgrade to AnyIO version 4.14.2 or later and update their dependency configuration files accordingly.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in