THREAT OPS › Threat News › [GHSA] GHSA-hp3v-5vw7-fx9w (high) — RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution
[GHSA] GHSA-hp3v-5vw7-fx9w (high) — RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution
GHSA-hp3v-5vw7-fx9w Severity: high CVE: CVE-2026-76825
RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution
### Impact RestrictedPython could allow a sandbox escape when a policy exposes the standard library `string` module, or otherwise exposes `string.Formatter`, to restricted code.
`string.Formatter` field resolution methods such as `get_field` can perform attr
Indicators of compromise
- CVE-2026-76825cve
Original source: https://github.com/advisories/GHSA-hp3v-5vw7-fx9w