{"id":"CVE-2023-41050","aliases":["GHSA-8xv7-89vj-q48c","PYSEC-2026-2075"],"title":"Information disclosure in AccessControl","summary":"Information disclosure in AccessControl","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","vendor":"accesscontrol","product":"accesscontrol","ecosystem":"pip","affected":["accesscontrol < 4.4","zope < 4.8.9","accesscontrol >= 5.0, < 5.8","accesscontrol >= 6.0, < 6.2","zope >= 5.0.0, < 5.8.4"],"patched":["accesscontrol 4.4","zope 4.8.9","accesscontrol 5.8","accesscontrol 6.2","zope 5.8.4"],"published":"2023-09-07","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-8xv7-89vj-q48c","references":[{"url":"https://github.com/zopefoundation/AccessControl/security/advisories/GHSA-8xv7-89vj-q48c"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41050"},{"url":"https://github.com/zopefoundation/AccessControl/commit/6bc32692e0d4b8d5cf64eae3d19de987c7375bc9"},{"url":"https://github.com/zopefoundation/AccessControl"}],"tags":["osv","pip"],"epss":0.00641,"epssPercentile":0.48495,"ingestedAt":"2026-07-08T18:25:47.570Z","slug":"CVE-2023-41050","body":"## Overview\n\n### Impact\nPython's \"format\" functionality allows someone controlling the format string to \"read\" objects accessible (recursively) via attribute access and subscription from accessible objects. Those attribute accesses and subscriptions use Python's full blown `getattr` and `getitem`, not the policy restricted `AccessControl` variants `_getattr_` and `_getitem_`. This can lead to critical information disclosure.\n\n`AccessControl` already provides a safe variant for `str.format` and denies access to `string.Formatter`. However, `str.format_map` is still unsafe.\n\nAffected are all users who allow untrusted users to create `AccessControl` controlled Python code and execute it.\n\n### Patches\nA fix will be introduced in the versions 4.4, 5.8 and 6.2.\n\n### Workarounds\nThere are no workarounds.\n\n### References\nhttps://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-xjw2-6jm9-rf67 describes the corresponding problem for `RestrictedPython`.\n\n\n## Affected packages\n\n- `accesscontrol < 4.4`\n- `zope < 4.8.9`\n- `accesscontrol >= 5.0, < 5.8`\n- `accesscontrol >= 6.0, < 6.2`\n- `zope >= 5.0.0, < 5.8.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `accesscontrol 4.4`\n- `zope 4.8.9`\n- `accesscontrol 5.8`\n- `accesscontrol 6.2`\n- `zope 5.8.4`","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}