CVE-2025-22153 – restrictedpython
Package
Manager: pip
Name: restrictedpython
Vulnerable Version: >=6.0 <8.0
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:L
EPSS: 0.0011 pctl0.30069
Details
try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter ### Impact Via a type confusion bug in the CPython interpreter when using `try/except*` RestrictedPython could be bypassed. We believe this should be fixed upstream in Python itself until that we remove support for `try/except*` from RestrictedPython. (It has been fixed for some Python versions.) ### Patches Patched in version 8.0 by removing support for `try/except*` clauses ### Workarounds There is no workaround. ### References none
Metadata
Created: 2025-01-23T17:19:34Z
Modified: 2025-01-23T23:17:21Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-gmj9-h825-chq2/GHSA-gmj9-h825-chq2.json
CWE IDs: ["CWE-843"]
Alternative ID: GHSA-gmj9-h825-chq2
Finding: F113
Auto approve: 1