PT-2026-93751 · Pypi · Restrictedpython
CVE-2026-76825
·
Published
2026-09-16
·
Updated
2026-10-01
CVSS v3.1
8.4
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RestrictedPython versions prior to 8.4
Description
A sandbox escape is possible when a custom import policy or globals expose the standard library
string module, the string.Formatter class, a Formatter instance, or a Formatter subclass to restricted code. The string.Formatter methods format(), get field(), get value(), and vformat() perform attribute and item traversal internally, bypassing the safer getattr protections. This allows restricted code to obtain live object references to reach function globals, builtins, file access, or code execution primitives, compromising the confidentiality, integrity, and availability of the host environment.Recommendations
Update to version 8.4.
Do not expose the standard library
string module or string.Formatter to restricted code.
If a custom import hook is used, deny imports of string or provide a restricted wrapper that does not expose Formatter.
Ensure neither string.Formatter nor Formatter instances are available in custom globals.Exploit
Fix
Protection Mechanism Failure
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Restrictedpython