THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hp3v-5vw7-fx9w (high) — RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution

[GHSA] GHSA-hp3v-5vw7-fx9w (high) — RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution

medgithub_advisoriesPublished 2026-09-17

GHSA-hp3v-5vw7-fx9w Severity: high CVE: CVE-2026-76825

RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution

### Impact RestrictedPython could allow a sandbox escape when a policy exposes the standard library `string` module, or otherwise exposes `string.Formatter`, to restricted code.

`string.Formatter` field resolution methods such as `get_field` can perform attr

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hp3v-5vw7-fx9w