THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pq59-9fq7-m886 (medium) — Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions

[GHSA] GHSA-pq59-9fq7-m886 (medium) — Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions

medgithub_advisoriesPublished 2026-09-17

GHSA-pq59-9fq7-m886 Severity: medium CVE: CVE-2026-77401

Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions

### Impact Python's string `format` functionality allows someone controlling the format string to "read" objects accessible (recursively) via attribute access and subscription from accessible objects. Those attribute accesses a

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pq59-9fq7-m886