CVE-2026-55830
published 2026-07-08CVE-2026-55830: RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to…
PriorityP342high8.3CVSS 3.1
AVNACLPRHUIRSCCHIHAL
EPSS
0.40%
32.0th percentile
RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted positional-only arguments, allowing __getattr__, _getitem_, _write_, or _print_ to be shadowed by a local parameter and bypass the embedding application's access policy. This issue is fixed in version 8.3.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zopefoundation | restrictedpython | < 8.3 | 8.3 |
| zopefoundation | restrictedpython | >= 0 < 8.3 | 8.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
RestrictedPython guard hooks can be shadowed via positional-only arguments
ghsa·2026-08-28
CVE-2026-55830 [HIGH] CWE-184 RestrictedPython guard hooks can be shadowed via positional-only arguments
RestrictedPython guard hooks can be shadowed via positional-only arguments
### Impact
RestrictedPython rewrites sensitive operations to go through guard hooks. Attribute access becomes `_getattr_(obj, name)`, item access becomes `_getitem_(obj, key)`, writes go through `_write_`, and print goes through `_print_`. The embedding application supplies these hooks to enforce its policy.
Argument-name validation rejects these protected names for regular arguments, `*args`, `**kwargs`, and keyword-only arguments, but it misses positional-only arguments (the ones before `/`). So a function like:
```python
def f(_getattr_=evil, /):
return o.x
```
makes `_getattr_` a local that shadows the policy hook, and the rewritten access calls `evil` instead. The same works for `_getitem_`, `_write_`, and
VulDB
zopefoundation RestrictedPython up to 8.2 Argument Validation check_function_argument_names Local access control
vuldb·2026-07-09·CVSS 8.3
CVE-2026-55830 [HIGH] zopefoundation RestrictedPython up to 8.2 Argument Validation check_function_argument_names Local access control
A vulnerability, which was classified as critical, has been found in zopefoundation RestrictedPython up to 8.2. Affected is the function check_function_argument_names of the component Argument Validation. This manipulation of the argument Local causes improper access controls.
This vulnerability is registered as CVE-2026-55830. Remote exploitation of the attack is possible. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-08
Published