{"id":"CVE-2025-24359","aliases":["GHSA-3wwr-3g9f-9gc7","PYSEC-2026-1195"],"url":"https://o3.security/vulnerability/CVE-2025-24359","summary":"ASTEVAL Vulnerable to Maliciously Crafted Format Strings Leading to Sandbox Escape","details":"ASTEVAL is an evaluator of Python expressions and statements. Prior to version 1.0.6, if an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute arbitrary Python code in the context of the application using the library. The vulnerability is rooted in how `asteval` performs handling of `FormattedValue` AST nodes. In particular, the `on_formattedvalue` value uses the dangerous format method of the str class. The code allows an attacker to manipulate the value of the string used in the dangerous call `fmt.format(__fstring__=val)`. This vulnerability can be exploited to access protected attributes by intentionally triggering an `AttributeError` exception. The attacker can then catch the exception and use its `obj` attribute to gain arbitrary access to sensitive or protected object properties. Version 1.0.6 fixes this issue.","published":"2025-01-24T16:52:44.304Z","modified":"2026-08-08T03:30:28.115798302Z","cvss":{"score":8.4,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"asteval","fixedVersion":"1.0.6"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/lmfit/asteval/blob/cfb57f0beebe0dc0520a1fbabc35e66060c7ea71/asteval/asteval.py#L507"},{"type":"WEB","url":"https://lucumr.pocoo.org/2016/12/29/careful-with-str-format"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24359.json"},{"type":"ADVISORY","url":"https://github.com/lmfit/asteval/security/advisories/GHSA-3wwr-3g9f-9gc7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24359"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:30:28.115798302Z"}}