{"id":"GHSA-pq59-9fq7-m886","summary":"Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions","details":"### Impact\nPython's string `format` functionality allows someone controlling the format string to \"read\" objects accessible (recursively) via attribute access and subscription from accessible objects. Those attribute accesses and subscriptions use Python's full blown `getattr` and `getitem`, not the policy restricted `AccessControl` variants `_getattr_` and `_getitem_`. This can lead to critical information disclosure.\n\nThe `AccessControl` package already guards against direct access to the formatting functions on string instances, but these mitigations did not cover subclasses of `str`.\n\nAffected are all users who allow untrusted users to create AccessControl controlled Python code and execute it.\n\n### Patches\nA fix was published with version 7.4.\n\n### Workarounds\nThere is no workaround.","aliases":["CVE-2026-77401","PYSEC-2026-4022"],"modified":"2026-10-01T17:56:05.701166603Z","published":"2026-09-17T16:30:37Z","database_specific":{"nvd_published_at":"2026-09-16T15:17:46Z","cwe_ids":["CWE-693"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-17T16:30:37Z"},"references":[{"type":"WEB","url":"https://github.com/zopefoundation/AccessControl/security/advisories/GHSA-pq59-9fq7-m886"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77401"},{"type":"WEB","url":"https://github.com/zopefoundation/AccessControl/commit/f980450eea416718be62847f34dfd51822938e43"},{"type":"PACKAGE","url":"https://github.com/zopefoundation/AccessControl"},{"type":"WEB","url":"https://github.com/zopefoundation/AccessControl/releases/tag/7.4"}],"affected":[{"package":{"name":"accesscontrol","ecosystem":"PyPI","purl":"pkg:pypi/accesscontrol"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.4"}]}],"versions":["2.13.0","2.13.1","2.13.10","2.13.11","2.13.12","2.13.13","2.13.14","2.13.15","2.13.16","2.13.2","2.13.3","2.13.4","2.13.5","2.13.6","2.13.7","2.13.8","2.13.9","3.0","3.0.1","3.0.10","3.0.11","3.0.12","3.0.13","3.0.14","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","4.0","4.0a1","4.0a2","4.0a3","4.0a4","4.0a5","4.0a6","4.0a7","4.0b1","4.0b2","4.0b3","4.0b4","4.0b5","4.0b6","4.0b7","4.1","4.2","4.3","4.4","5.0","5.1","5.2","5.3","5.3.1","5.4","5.5","5.6","5.7","6.0","6.1","6.2","6.3","7.0","7.1","7.2","7.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-pq59-9fq7-m886/GHSA-pq59-9fq7-m886.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N"}]}