© 2025-2026 PySpect
First version without a known vulnerability: 1.0.9
asteval has a Sandbox Escape via BaseException Subclasses
Fixed in: 1.0.9
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
Fixed in: 1.0.9
ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape
Fixed in: 1.0.6
ASTEVAL Allows Malicious Tampering of Exposed AST Nodes Leads to Sandbox Escape
Fixed in: 1.0.6