CVE-2025-22153 describes a bypass vulnerability in RestrictedPython versions prior to 8.0, stemming from a type confusion bug in CPython interpreters (3.11 to 3.13.1) when handling try/except* clauses. This flaw allows an attacker to escape the restricted Python environment. With a CVSS score of 7.9 (HIGH), successful exploitation could lead to high confidentiality and integrity impacts, and low availability impact, requiring high privileges and complex attack conditions. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Zopefoundation | RestrictedPython | >= 6.0, < 8.0CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.