Fetching from the wire…
Security2026-08-28 · source-backed
The executor inspected submitted source against a denied list of attribute names and calls, leaving the attribute-access escapes that always defeat that approach, with no authentication in front of it (NVD). Denylist sandboxing of Python loses reliably. The boundary has to be a process or a container.
Each link below shares sources, entities, or timing with this story.
Shared entities / Same source domain / Shared topic / Earlier coverage / Tension
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); overlapping topics (against, call).
Claude Code uses Python / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (Claude Code uses Python); both cover CVE, NVD; reported by the same outlet (nvd.nist.gov).
Shared entities / Same source domain / Earlier coverage / Tension
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); earlier CVE coverage from 2026-08-27.
Claude Code uses Python / Shared entities / Earlier coverage
Linked by a graph relationship (Claude Code uses Python); both cover CVE, NVD; earlier CVE coverage from 2026-08-09.
OpenFang competes with Python / Shared entity: Python / Earlier coverage / Tension
Linked by a graph relationship (OpenFang competes with Python); both cover Python; earlier Python coverage from 2026-03-01.
Shared entities / Same source domain / Earlier coverage
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); earlier CVE coverage from 2026-08-27.
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); earlier CVE coverage from 2026-08-27.
Both cover CVE, NVD; reported by the same outlet (nvd.nist.gov); earlier CVE coverage from 2026-08-25.