CVE-2025-22153: try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
Impact Via a type confusion bug in the CPython interpreter when using try/except RestrictedPython could be bypassed.
We believe this should be fixed upstream in Python itself until that we remove support for try/except from RestrictedPython. (It has been fixed for some Python versions.)
Patches Patched in version 8.0 by removing support for try/except clauses
Workarounds There is no workaround.
References none
Other sources
RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Via a type confusion bug in versions of the CPython interpreter starting in 3.11 and prior to 3.13.2 when using try/except, RestrictedPython starting in version 6.0 and prior to version 8.0 could be bypassed. The issue is patched in version 8.0 of RestrictedPython by removing support for try/except clauses. No known workarounds are available.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22153?
CVE-2025-22153 is categorized as a medium severity vulnerability due to the potential for type confusion in the CPython interpreter.
How do I fix CVE-2025-22153?
To fix CVE-2025-22153, you should upgrade RestrictedPython to a version above 8.0 or remove support for 'try/except*' from RestrictedPython until an official patch is released.
Which versions of RestrictedPython are affected by CVE-2025-22153?
CVE-2025-22153 affects RestrictedPython versions between 6.0 and 8.0.
Which versions of CPython are impacted by CVE-2025-22153?
CVE-2025-22153 impacts CPython versions from 3.11 to 3.13.2.
What is RestrictedPython?
RestrictedPython is a Python library designed to safely execute untrusted Python code.