PT-2026-93751 · Pypi · Restrictedpython

CVE-2026-76825

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RestrictedPython versions prior to 8.4
Description A sandbox escape is possible when a custom import policy or globals expose the standard library string module, the string.Formatter class, a Formatter instance, or a Formatter subclass to restricted code. The string.Formatter methods format(), get field(), get value(), and vformat() perform attribute and item traversal internally, bypassing the safer getattr protections. This allows restricted code to obtain live object references to reach function globals, builtins, file access, or code execution primitives, compromising the confidentiality, integrity, and availability of the host environment.
Recommendations Update to version 8.4. Do not expose the standard library string module or string.Formatter to restricted code. If a custom import hook is used, deny imports of string or provide a restricted wrapper that does not expose Formatter. Ensure neither string.Formatter nor Formatter instances are available in custom globals.

Exploit

Fix

Protection Mechanism Failure

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76825
ECHO-D1EF-A46C-F47D
GHSA-HP3V-5VW7-FX9W
PYSEC-2026-4161

Affected Products

Restrictedpython