GHSA-5rfv-66g4-jr8h
GitHub Security Advisory
RestrictedPython information leakage via `AttributeError.obj` and the `string` module
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
### Impact
A user can gain access to protected (and potentially sensible) information indirectly via `AttributeError.obj` and the `string` module.
### Patches
The problem will be fixed in version 7.3.
### Workarounds
If the application does not require access to the module `string`, it can remove it from `RestrictedPython.Utilities.utility_builtins` or otherwise do not make it available in the restricted execution environment.
Affected Packages
PyPI
RestrictedPython
Affected versions:
0
(fixed in 7.3)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.