PatchSiren

amoffat CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH amoffat CVE published 2026-08-18

CVE-2026-54552

CVE-2026-54552 is a high-severity vulnerability in the sh Python package, which provides process launching capabilities. The vulnerability allows an attacker to retain access to sensitive files and resources by exploiting an incomplete privilege drop on Linux and Unix-like systems. This issue has been fixed in version 2.2.4. The vulnerability arises when sh runs from an elevated process and launches a com [truncated]