{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-76825/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:restrictedpython:restrictedpython:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.4,"id":"CVE-2026-76825"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RestrictedPython (\u003c 8.4)"],"_cs_severities":["high"],"_cs_tags":["sandbox-escape","cve-2026-76825","python"],"_cs_type":"advisory","_cs_vendors":["RestrictedPython"],"content_html":"\u003cp\u003eRestrictedPython, a package designed to provide a sandbox environment for executing untrusted Python code, contains a vulnerability identified as CVE-2026-76825. This vulnerability allows for a sandbox escape if an application policy exposes the standard library 'string' module or the 'string.Formatter' class to the restricted environment.\u003c/p\u003e\n\u003cp\u003eThe issue stems from how 'string.Formatter' performs field resolution. Specifically, internal methods such as 'get_field' can perform attribute and item traversal that bypasses RestrictedPython's established attribute guards. By leveraging this behavior, an attacker capable of executing code within the restricted environment can obtain references to sensitive objects. These objects may include function globals, builtins, and code execution primitives, potentially enabling the attacker to break out of the sandbox to perform arbitrary operations on the underlying host system. This vulnerability affects all versions of RestrictedPython prior to 8.4.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a severe risk to any application relying on RestrictedPython to safely execute untrusted user-supplied code. If successfully exploited, an attacker could escalate privileges from the restricted sandbox to the host environment, leading to full application compromise, unauthorized data access, or arbitrary code execution. The scope of impact is dependent on the application's configuration and the level of access granted to the 'string' module within its restricted environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the 'RestrictedPython' package to version 8.4 or later immediately to apply the fix in 'safer_getattr'.\u003c/li\u003e\n\u003cli\u003eReview custom import policies to ensure the 'string' module and 'string.Formatter' class are not exposed to restricted execution environments.\u003c/li\u003e\n\u003cli\u003eAudit custom global configurations passed to RestrictedPython to ensure neither 'string.Formatter' nor instances of it are accessible to untrusted code.\u003c/li\u003e\n\u003cli\u003eImplement a policy of least privilege by restricting access to standard library modules within the Python sandbox environment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T19:14:05Z","date_published":"2026-09-17T19:14:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-restrictedpython-sandbox-escape/","summary":"RestrictedPython versions prior to 8.4 are vulnerable to a sandbox escape (CVE-2026-76825) via the string.Formatter module, which can bypass attribute guards to access sensitive objects and primitives.","title":"RestrictedPython Sandbox Escape via string.Formatter","url":"https://feed.craftedsignal.io/briefs/2026-09-restrictedpython-sandbox-escape/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-76825","version":"https://jsonfeed.org/version/1.1"}