RestrictedPython guard hooks can be shadowed through positional-only arguments
- Sources: advisory, NVD
- Summary: GitHub advisory GHSA-ffg3-p8fm-mjx2, tracked as CVE-2026-55830, states that RestrictedPython's guard hooks can be shadowed through positional-only arguments. The fix is in RestrictedPython 8.3.
- Why it matters: Any application embedding RestrictedPython as a sandbox can have its access policy bypassed until it moves to 8.3.