PYSEC-2026-3540
sh _uid does not drop supplementary groups (incomplete privilege drop)
Quick fix
PYSEC-2026-3540 — sh: upgrade to the fixed version with the command below.
pip install --upgrade 'sh>=2.2.4'Details
### Impact The `_uid` option performed an incomplete privilege drop on Linux/Unix-like systems.
When `sh` was run from a process with elevated privileges, such as root, and a command was launched with `_uid=<unprivileged user>`, the child process changed its UID and primary GID but did not reset its supplementary groups. As a result, the child process could retain the parent process’s supplementary groups, potentially including privileged groups such as root, docker, disk, shadow, or sudo.
This could allow a subprocess that was expected to run with reduced privileges to access files or resources available to the original process’s supplementary groups. Users are impacted if they rely on `_uid` as a privilege boundary when launching commands from a privileged parent process.
### Patches Upgrade to version >= 2.2.4
### Workarounds Avoid using `_uid` when the user represents a less-privileged user.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/amoffat/sh/security/advisories/GHSA-q38v-wp89-2w55[WEB]
- https://github.com/amoffat/sh[PACKAGE]
- https://github.com/amoffat/sh/releases/tag/2.2.4[WEB]
- https://pypi.org/project/sh[PACKAGE]
- https://github.com/advisories/GHSA-q38v-wp89-2w55[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-54552[ADVISORY]