Repository navigation
[CVE-2026-2297] SourcelessFileLoader does not use io.open_code() #145506
Copy link
Copy link
Closed
Labels
3.12only security fixesonly security fixesstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytopic-importlibtype-securityA security issueA security issue
Description
Activity
- addedtype-securityA security issueA security issue3.11only security fixesonly security fixes3.10 (EOL)end of lifeend of life3.12only security fixesonly security fixes3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15bugs and security fixesbugs and security fixes
on Mar 4, 2026 - addedstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory
on Mar 4, 2026 - added 3 commits that reference this issue
on Mar 4, 2026 9 remaining items
- added 2 commits that reference this issue
on Apr 12, 2026 - removed3.11only security fixesonly security fixes3.10 (EOL)end of lifeend of life3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15bugs and security fixesbugs and security fixes
on Jun 2, 2026 - added 2 commits that reference this issue
on Jul 22, 2026 - added a commit that references this issue
on Aug 14, 2026
Metadata
Metadata
Assignees
Labels
3.12only security fixesonly security fixesstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytopic-importlibtype-securityA security issueA security issue
The import hook in CPython that handles legacy
*.pycfiles (SourcelessFileLoader) is incorrectly handled inFileLoader(a base class) and so does not useio.open_code()to read the.pycfiles. This means anyone who has hookedio.open_code()to do validation will be bypassed.The
SourcelessFileLoadersubclass doesn't get caught by theisinstance()call, because it's neither of the classes listed. It should haveSourcelessFileLoaderadded to the tuple.This import hook is enabled by default, though the
SourceFileLoaderis higher priority, and it does correctly useio.open_code().Legacy
*.pycfiles may be used if a user has precompiled their sources and then removed the source code. Under default configuration, it will never be used.I didn't find any GitHub results that were actual uses, though I expected they'd all be private forks anyway, so I think the impact is going to be very low. The fix is trivial, but this is also easily exploitable if it's the sole security measure - for any module that's going to be imported, put its
.pycearlier on the search path and that'll be picked first without verification.(This has already been reviewed by the PSRT and assigned CVE-2026-2297. The issue is just to get the fix merged.)
Linked PRs