Skip to content

Update dependency sh to v2 [SECURITY] - #166

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/pypi-sh-vulnerability
Open

Update dependency sh to v2 [SECURITY]#166
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/pypi-sh-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jul 17, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
sh ==1.14.2==2.2.4 age confidence

sh _uid does not drop supplementary groups (incomplete privilege drop)

CVE-2026-54552 / GHSA-q38v-wp89-2w55

More information

Details

Impact

The _uid option performed an incomplete privilege drop on Linux/Unix-like systems.

When sh was run from a process with elevated privileges, such as root, and a command was launched with _uid=<unprivileged user>, the child process changed its UID and primary GID but did not reset its supplementary groups. As a result, the child process could retain the parent process’s supplementary groups, potentially including privileged groups such as root, docker, disk, shadow, or sudo.

This could allow a subprocess that was expected to run with reduced privileges to access files or resources available to the original process’s supplementary groups. Users are impacted if they rely on _uid as a privilege boundary when launching commands from a privileged parent process.

Patches

Upgrade to version >= 2.2.4

Workarounds

Avoid using _uid when the user represents a less-privileged user.

Severity

  • CVSS Score: 7.9 / 10 (High)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

amoffat/sh (sh)

v2.2.4

Compare Source

  • Bugfix regression where correct gid was not set on the launched process

v2.2.3

Compare Source

  • Bugfix where supplemental groups were not dropped when using _uid

v2.2.2

Compare Source

  • Bugfix where it was impossible to use a signal as an ok_code #​699

v2.2.1

Compare Source

  • Bugfix where async and return_cmd does not raise exceptions #​746

v2.2.0

Compare Source

  • return_cmd with await now works correctly #​743
  • Formal support for Python 3.12

v2.1.0

Compare Source

  • Add contrib command sh.contrib.bash #​736

v2.0.7

Compare Source

  • Fix sh.glob arguments #​708
  • Misc modernizations

v2.0.6

Compare Source

  • Add back appropriate sdist files comment

v2.0.5

Compare Source

  • Allow nested with contexts #​690
  • Call correct asyncio function for getting event loop #​683

v2.0.4

Compare Source

  • Allow ok_code to be used with fg #​665
  • Make sure new_group never creates a new session #​675

v2.0.3

Compare Source

  • Performance regression when using a generator with _in #​650
  • Adding test support for python 3.11

v2.0.2

Compare Source

  • Performance regression when using a generator with _in #​650
  • Adding test support for python 3.11

v2.0.1

Compare Source

v2.0.0

Compare Source

  • Executed commands now return a unicode string by default
  • Removed magical module-like execution contexts #​636
  • Added basic asyncio support via _async
  • Dropped support for Python < 3.8
  • Bumped default tty size to more standard (24, 80)
  • First argument being a RunningCommand no longer automatically passes it as stdin
  • RunningCommand.__eq__ no longer has the side effect of executing the command #​518
  • _tee now supports both "err" and "out" #​215
  • Removed the builtin override cd link
  • Altered process launching model to behave more expectedly #​495
  • Bugfix where _no_out isn't allowed with _iter="err" #​638
  • Allow keyword arguments to have a list of values #​529

v1.14.3

Compare Source

  • Bugfix where Command was not aware of default call args when wrapping the module #​559

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title Update dependency sh to v2 [SECURITY] Update dependency sh to v2 [SECURITY] - autoclosed Jul 22, 2026
@renovate renovate Bot closed this Jul 22, 2026
@renovate
renovate Bot deleted the renovate/pypi-sh-vulnerability branch July 22, 2026 00:02
@renovate renovate Bot changed the title Update dependency sh to v2 [SECURITY] - autoclosed Update dependency sh to v2 [SECURITY] Jul 22, 2026
@renovate renovate Bot reopened this Jul 22, 2026
@renovate
renovate Bot force-pushed the renovate/pypi-sh-vulnerability branch 2 times, most recently from 192e053 to 9b827cd Compare July 22, 2026 01:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants