Impact
RestrictedPython allows sandbox escape when a custom import policy or globals expose the standard library string module, the string.Formatter class, a Formatter instance, or a Formatter subclass to restricted code. The string.Formatter methods format, get_field, get_value, and vformat perform attribute and item traversal internally without passing through RestrictedPython's safer_getattr protections, allowing restricted code to reach function globals, builtins, file access, or code execution primitives, thereby affecting confidentiality, integrity, and availability.
Affected Systems
Zope Foundation's RestrictedPython library, versions earlier than 8.4, are affected when the library is configured to expose the string module or its Formatter components to limited code.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.4, with an EPSS score of less than 1% and it is not listed in the CISA KEV catalog. Exploitation requires an application that uses RestrictedPython with an import policy or globals that expose the string module or Formatter, allowing sandbox escape and potentially arbitrary code execution. Organizations should assess whether their deployments permit such exposure and patch accordingly.
OpenCVE Enrichment
Github GHSA