CVE-2026-63349High· 7.0▾ TwilightAnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_proce…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_process() forwards the group argument to the backend instead of extra_groups. A caller that supplies extra_groups=[] to clear inherited supplementary groups can therefore launch a child that retains the parent process groups, undermining a privilege-dropping boundary. If group is also supplied, the integer group value is passed where an iterable of supplementary groups is expected and the launch can fail with TypeError. This issue affects POSIX applications that rely on AnyIO subprocess helpers to launch less-privileged child processes. This issue is fixed in version 4.14.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
anyio >= 4.14.0, < 4.14.2Patched in:
anyio 4.14.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-64847Medium· 6.8AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio
CVE-2026-63374CriticalAnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
CVE-2026-94048Medium· 6.6A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0
CVE-2026-94047Medium· 6.3A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32
CVE-2026-93968Low· 3.8A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1
CVE-2026-92015High· 8.8Privilege escalation in the WebExtensions component