restrictedpython
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting restrictedpythonpage 1 of 1
- CVE-2023-37271HIGHCVSS 8.4EG 8.4✓ Fixed in 5.32023-07-11
vulnerable: 3.4.2 ... 5.3a1.dev0 (24 versions)
RestrictedPython is a tool that helps to define a subset of the Python language which allows users to provide a program input into a trusted environment. RestrictedPython does not check access to stack frames and their attributes. Stack fr…
- CVE-2023-41039HIGHCVSS 8.3EG 8.3✓ Fixed in 5.42023-08-30
vulnerable: 3.4.2 ... 6.1 (27 versions)
RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling the format string to "read" all objects accessible through recursive attribute lookup and s…
- CVE-2024-47532MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.32024-09-30
vulnerable: 3.4.2 ... 7.2a1.dev0 (37 versions)
RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will b…
- CVE-2025-22153HIGHCVSS 7.9EG 7.9✓ Fixed in 8.02025-01-23
vulnerable: 6.0 ... 7.4 (12 versions)
RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Via a type confusion bug in versions of the CPython interpreter starting in 3.11 and prior …
Check whether restrictedpython is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for restrictedpython CVEs against the assets you own.
Start Free Scan →