GHSA-q94g-3gcf-66x7

Suggest an improvement
Source
https://github.com/advisories/GHSA-q94g-3gcf-66x7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-q94g-3gcf-66x7/GHSA-q94g-3gcf-66x7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q94g-3gcf-66x7
Aliases
  • CVE-2026-35370
Related
Published
2026-04-22T18:31:46Z
Modified
2026-06-02T13:29:24.287658320Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
uutils coreutils has an Incorrect Authorization issue
Details

The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely on the output of id to make security-critical access-control or permission decisions, this discrepancy can lead to unauthorized access or security misconfigurations.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-30T17:51:17Z",
    "nvd_published_at": "2026-04-22T17:16:40Z",
    "severity": "MODERATE"
}
References

Affected packages

crates.io / coreutils

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.8.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-q94g-3gcf-66x7/GHSA-q94g-3gcf-66x7.json"