THREAT OPS › Threat News › [GHSA] GHSA-pq59-9fq7-m886 (medium) — Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
[GHSA] GHSA-pq59-9fq7-m886 (medium) — Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
GHSA-pq59-9fq7-m886 Severity: medium CVE: CVE-2026-77401
Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
### Impact Python's string `format` functionality allows someone controlling the format string to "read" objects accessible (recursively) via attribute access and subscription from accessible objects. Those attribute accesses a
Indicators of compromise
- CVE-2026-77401cve
Original source: https://github.com/advisories/GHSA-pq59-9fq7-m886