THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9w56-46f6-3qhx (medium) — asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

[GHSA] GHSA-9w56-46f6-3qhx (medium) — asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

medgithub_advisoriesPublished 2026-08-20

GHSA-9w56-46f6-3qhx Severity: medium CVE: None

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

### Summary With its default configuration (numpy enabled, `import` disabled), asteval's `Interpreter` lets an attacker-controlled expression obtain a raw **arbitrary process-memory read and write** primitive, without using `import`, any `__dun

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9w56-46f6-3qhx