logo

The Glass Sandbox – The Complexity of Python Sandboxing 

ID: b2242b27-844a-5ce3-ac94-29f92d940264

STIX ID: report--b2242b27-844a-5ce3-ac94-29f92d940264

Feed Name: Checkmarx Zero

Threat Score
60/100

Date Published: 2025-03-26

Date Updated: 2026-04-27

Author: Alex Shleymovich

...
...

**Executive summary:** This article demonstrates how Python's object hierarchy and dunder attribute traversal can defeat scope-based sandboxes, using pandas.eval() as a concrete example to achieve remote code execution; it warns that blocklists are brittle and advocates avoiding eval-like constructs, applying OS-level isolation/segmentation, and using SAST and safer parsers to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.