Description
RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class, a Formatter instance, or a Formatter subclass to restricted code. The string.Formatter methods format, get_field, get_value, and vformat performed attribute and item traversal internally without passing through RestrictedPython's safer_getattr protections. Restricted code could use those live object references to reach function globals, builtins, file access, or code execution primitives, affecting confidentiality, integrity, and availability in the host environment. This issue is fixed in version 8.4.
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox escape leading to arbitrary code execution
Action: Patch
AI Analysis

Impact

RestrictedPython allows sandbox escape when a custom import policy or globals expose the standard library string module, the string.Formatter class, a Formatter instance, or a Formatter subclass to restricted code. The string.Formatter methods format, get_field, get_value, and vformat perform attribute and item traversal internally without passing through RestrictedPython's safer_getattr protections, allowing restricted code to reach function globals, builtins, file access, or code execution primitives, thereby affecting confidentiality, integrity, and availability.

Affected Systems

Zope Foundation's RestrictedPython library, versions earlier than 8.4, are affected when the library is configured to expose the string module or its Formatter components to limited code.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.4, with an EPSS score of less than 1% and it is not listed in the CISA KEV catalog. Exploitation requires an application that uses RestrictedPython with an import policy or globals that expose the string module or Formatter, allowing sandbox escape and potentially arbitrary code execution. Organizations should assess whether their deployments permit such exposure and patch accordingly.

Generated by OpenCVE AI on September 18, 2026 at 02:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade RestrictedPython to version 8.4 or later, which removes the escape path.
  • If upgrading is not possible immediately, configure the import policy and globals to prevent exposure of the string module and any Formatter classes or instances to restricted code.
  • Review and minimize custom import policies to only include safe modules and verify that safer_getattr protections are enabled.

Generated by OpenCVE AI on September 18, 2026 at 02:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hp3v-5vw7-fx9w RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution
History

Thu, 17 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Zope
Zope restrictedpython
Vendors & Products Zope
Zope restrictedpython

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class, a Formatter instance, or a Formatter subclass to restricted code. The string.Formatter methods format, get_field, get_value, and vformat performed attribute and item traversal internally without passing through RestrictedPython's safer_getattr protections. Restricted code could use those live object references to reach function globals, builtins, file access, or code execution primitives, affecting confidentiality, integrity, and availability in the host environment. This issue is fixed in version 8.4.
Title RestrictedPython: Sandbox escape via string.Formatter field resolution
Weaknesses CWE-200
CWE-470
CWE-680
CWE-693
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Zope Restrictedpython
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:35:53.779Z

Reserved: 2026-08-19T19:52:28.214Z

Link: CVE-2026-76825

cve-icon Vulnrichment

Updated: 2026-09-16T18:23:22.216Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:17:46.000

Modified: 2026-09-16T19:17:34.720

Link: CVE-2026-76825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-470

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

  • CWE-680

    Integer Overflow to Buffer Overflow

  • CWE-693

    Protection Mechanism Failure