Arbitrary Code Injection Affecting restrictedpython package, versions *


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.08% (37th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2004-RESTRICTEDPYTHON-5876551
  • published18 Mar 2025
  • disclosed30 Aug 2023

Introduced: 30 Aug 2023

CVE-2023-41039  (opens in a new tab)
CWE-74  (opens in a new tab)

How to fix?

There is no fixed version for Ubuntu:20.04 restrictedpython.

NVD Description

Note: Versions mentioned in the description apply only to the upstream restrictedpython package and not the restrictedpython package as distributed by Ubuntu. See How to fix? for Ubuntu:20.04 relevant fixed versions and status.

RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling the format string to "read" all objects accessible through recursive attribute lookup and subscription from objects he can access. This can lead to critical information disclosure. With RestrictedPython, the format functionality is available via the format and format_map methods of str (and unicode) (accessed either via the class or its instances) and via string.Formatter. All known versions of RestrictedPython are vulnerable. This issue has been addressed in commit 4134aedcff1 which has been included in the 5.4 and 6.2 releases. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS Base Scores

version 3.1