CPE
RestrictedPython (<= 8.2) fails to validate positional-only arguments, allowing an attacker to shadow security guard hooks (_getattr_, _getitem_, _write_, _print_) and bypass sandbox access policies.