PT-2026-56605 · Pypi · Restrictedpython

CVE-2026-55830

·

Published

2026-07-08

·

Updated

2026-09-10

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions RestrictedPython versions prior to 8.3
Description The check function argument names() function fails to reject protected guard hook names when they are used as positional-only arguments. This allows local parameters to shadow protected names such as getattr, getitem, write, or print, which can lead to a bypass of the embedding application's access policy.
Recommendations Update to version 8.3.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55830
GHSA-FFG3-P8FM-MJX2
PYSEC-2026-3917

Affected Products

Restrictedpython