Sandbox escape due to information disclosure via str.format (CVE-2016-10745). str.format_map allows sandbox escape (CVE-2019-10906).
{ "section": "core" }