{"id":"CVE-2024-40647","aliases":["GHSA-g92j-qhmh-64v2","PYSEC-2026-1917"],"title":"Sentry's Python SDK unintentionally exposes environment variables to subprocesses","summary":"Sentry's Python SDK unintentionally exposes environment variables to subprocesses","severity":"low","cvss":2.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N","vendor":"sentry-sdk","product":"sentry-sdk","ecosystem":"pip","affected":["sentry-sdk >= 2.0.0a1, < 2.8.0","sentry-sdk < 1.45.1"],"patched":["sentry-sdk 2.8.0","sentry-sdk 1.45.1"],"published":"2024-07-18","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-g92j-qhmh-64v2","references":[{"url":"https://github.com/getsentry/sentry-python/security/advisories/GHSA-g92j-qhmh-64v2"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-40647"},{"url":"https://github.com/getsentry/sentry-python/pull/3251"},{"url":"https://github.com/getsentry/sentry-python/commit/763e40aa4cb57ecced467f48f78f335c87e9bdff"},{"url":"https://docs.python.org/3/library/subprocess.html"},{"url":"https://docs.sentry.io/platforms/python/integrations/default-integrations"},{"url":"https://docs.sentry.io/platforms/python/integrations/default-integrations/#stdlib"},{"url":"https://github.com/getsentry/sentry-python"},{"url":"https://github.com/getsentry/sentry-python/releases/tag/1.45.1"},{"url":"https://github.com/getsentry/sentry-python/releases/tag/2.8.0"},{"url":"https://lists.debian.org/debian-lts-announce/2026/06/msg00001.html"}],"tags":["osv","pip"],"epss":0.002,"epssPercentile":0.10064,"ingestedAt":"2026-07-08T18:25:49.683Z","slug":"CVE-2024-40647","body":"## Overview\n\n### Impact\n\nThe bug in Sentry's Python SDK <2.8.0 results in the unintentional exposure of environment variables to subprocesses despite the `env={}` setting.\n\n### Details\n\nIn Python's `subprocess` calls, all environment variables are passed to subprocesses by default. However, if you specifically do not want them to be passed to subprocesses, you may use `env` argument in `subprocess` calls, like in this example:\n\n```\n>>> subprocess.check_output([\"env\"], env={\"TEST\":\"1\"})\nb'TEST=1\\n'\n```\n\nIf you'd want to not pass any variables, you can set an empty dict:\n\n```\n>>> subprocess.check_output([\"env\"], env={})\nb''\n```\n\nHowever, the bug in Sentry SDK <2.8.0 causes **all environment variables** to be passed to the subprocesses when `env={}` is set, unless the Sentry SDK's [Stdlib](https://docs.sentry.io/platforms/python/integrations/default-integrations/#stdlib) integration is disabled. The Stdlib integration is enabled by default.\n\n### Patches\nThe issue has been patched in https://github.com/getsentry/sentry-python/pull/3251 and the fix released in [sentry-sdk==2.8.0](https://github.com/getsentry/sentry-python/releases/tag/2.8.0). The fix was also backported to [sentry-sdk==1.45.1](https://github.com/getsentry/sentry-python/releases/tag/1.45.1).\n\n### Workarounds\n\nWe strongly recommend upgrading to the latest SDK version. However, if it's not possible, and if passing environment variables to child processes poses a security risk for you, there are two options:\n\n1. In your application, replace `env={}` with the minimal dict `env={\"EMPTY_ENV\":\"1\"}` or similar.\n\nOR\n\n2. Disable Stdlib integration:\n```\nimport sentry_sdk\n\n# Should go before sentry_sdk.init\nsentry_sdk.integrations._DEFAULT_INTEGRATIONS.remove(\"sentry_sdk.integrations.stdlib.StdlibIntegration\")\n\nsentry_sdk.init(...)\n```\n\n### References\n* Sentry docs: [Default integrations](https://docs.sentry.io/platforms/python/integrations/default-integrations/)\n* Python docs: [subprocess module](https://docs.python.org/3/library/subprocess.html)\n* Patch https://github.com/getsentry/sentry-python/pull/3251\n\n## Affected packages\n\n- `sentry-sdk >= 2.0.0a1, < 2.8.0`\n- `sentry-sdk < 1.45.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `sentry-sdk 2.8.0`\n- `sentry-sdk 1.45.1`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}