Executive brief
The 'sh' Python library, used for calling system commands, fails to fully restrict permissions when switching to a less-privileged user. This allows a sub-program to inherit sensitive access rights from its parent, such as administrative or system-level group memberships. An attacker or a compromised sub-process could use these inherited permissions to access restricted files or system resources they should not be able to see.
Technical details
The vulnerability is classified as CWE-273 (Improper Check for Dropped Privileges) within the 'sh' Python library. When using the '_uid' parameter to launch a command as an unprivileged user from a privileged parent (like root), the library correctly sets the UID and primary GID but fails to clear supplementary groups. Consequently, the child process retains access to privileged groups such as 'docker', 'sudo', or 'shadow'. This local attack requires the parent process to have elevated privileges. The issue is resolved in version 2.2.4 by ensuring supplementary groups are properly reset during the privilege drop.
Affected products
- amoffat sh < 2.2.4
Timeline
- 2026-06-05: disclosed: Initial disclosure in amoffat/sh repository
- 2026-07-17: advisory: GitHub Advisory published
- 2026-07-17: patched: Fix released in version 2.2.4