<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T08:55:14.618769+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-76825</id>
    <title>CVE-2026-76825 — RestrictedPython: Sandbox escape via string.Formatter field resolution</title>
    <updated>2026-10-02T08:55:14.620616+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> zopefoundation RestrictedPython</p>
<p>RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class, a Formatter instance, or a Formatter subclass to restricted code. The string.Formatter methods format, get_field, get_value, and vformat performed attribute and item traversal internally without passing through RestrictedPython's safer_getattr protections. Restricted code could use those live object references to reach function globals, builtins, file access, or code execution primitives, affecting confidentiality, integrity, and availability in the host environment. This issue is fixed in version 8.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-76825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hp3v-5vw7-fx9w</id>
    <title>GHSA-hp3v-5vw7-fx9w — RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution</title>
    <updated>2026-10-02T08:55:14.620692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: RestrictedPython</p>
<p>### Impact
RestrictedPython could allow a sandbox escape when a policy exposes the standard library `string` module, or otherwise exposes `string.Formatter`, to restricted code.</p>
<p>`string.Formatter` field resolution methods such as `get_field` can perform attribute and item traversal internally and return live object references. This can bypass RestrictedPython's normal attribute guards and may allow access to sensitive objects such as function globals, builtins, file access, or code execution primitives.</p>
<p>Users are impacted if they run untrusted code with RestrictedPython and expose `string.Formatter`, directly or indirectly, for example through a custom import policy or globals.</p>
<p>### Patches
The problem has been patched by blocking access to `string.Formatter` and unsafe `string.Formatter` traversal methods in `safer_getattr`.</p>
<p>Users should upgrade to the patched release once available. Affected and patched version numbers should be filled in when the release is published.</p>
<p>### Workarounds
Do not expose the standard library `string` module or `string.Formatter` to restricted code.</p>
<p>If a custom import hook is used, deny imports of `string` or provide only a restricted wrapper that does not expose `Formatter`. If custom globals are supplied, ensure neither `string.Formatter` nor `Formatter` instances are available to restricted code.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hp3v-5vw7-fx9w"/>
  </entry>
</feed>
