CVE-2026-63349
— UNSCOREDpublic exploit availablePublished 2026-09-18 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_process() forwards the group argument to the backend instead of extra_groups. A caller that supplies extra_groups=[] to clear inherited supplementary groups can therefore launch a child that retains the parent process groups, undermining a privilege-dropping boundary. If group is also supplied, the integer group value is passed where an iterable of supplementary groups is expected and the launch can fail with TypeError. This issue affects POSIX applications that rely on AnyIO subprocess helpers to launch less-privileged child processes. This issue is fixed in version 4.14.2.
Weaknesses
CWE-266, CWE-269
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-101860PoC
- LOWCVE-2026-93968PoC
- MEDIUMCVE-2026-94047PoC
- MEDIUMCVE-2026-94048PoC
- HIGHCVE-2026-94425
- MEDIUMCVE-2026-97895PoC
- HIGHCVE-2025-71421PoC
- HIGHCVE-2026-100578PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.