Vulnerability in str.format() in Python Last Updated : 06 Jan, 2025 Summarize Comments Improve Suggest changes Share Like Article Like Report str.format() is one of the string formatting methods in Python, which allows multiple substitutions and value formatting. This method lets us concatenate elements within a string through positional formatting. But the vulnerability comes when our Python app uses str.format in the user-controlled string. Let’s understand with the help of an example: Python # Sensitive configuration data CONFIG = { "KEY": "ASXFYFGK78989" } class Person: def __init__(self, s1, s2): self.s1 = s1 self.s2 = s2 def fun(template, person): return template.format(person_obj=person) # Create a person object person = Person("GEEKS", "FORGEEKS") # Case 1: Safe input a= "Avatar_{person_obj.s1}_{person_obj.s2}" print(fun(a, person)) # Case 2: Malicious input b= "{person_obj.__init__.__globals__[CONFIG][KEY]}" print(fun(b, person)) OutputAvatar_GEEKS_FORGEEKS ASXFYFGK78989 Explanation:Person Class: This class defines a template for creating people with s1 and s2 attributes.fun Function: This function dynamically formats a string using the person object.Case 1 (Safe input):This is the expected, safe result, where the placeholders are replaced with valid values from the person object.Case 2(Malicious Input):This is a dangerous situation where a malicious user can exploit the str.format() method to retrieve sensitive data from the global context.Table of ContentWhy is Case 2 a Vulnerability?Using f-stringsUsing string.Template classWhy is Case 2 a Vulnerability?str.format() method can evaluate expressions within the format string, allowing access to variables and object details. This means a user can manipulate the input to access sensitive data, like the CONFIG dictionary. This creates a security risk because attackers could retrieve information they should not have access to.Using f-stringsf-strings provide a more controlled way of formatting strings and do not evaluate arbitrary expressions. They are safer and faster than str.format(). Python class Person: def __init__(self, s1, s2): self.s1 = s1 self.s2= s2 # Create a person object person = Person("Geeks", "ForGeeks") # Use f-string for formatting a = f"Avatar_{person.s1}_{person.s2}" print(a) OutputAvatar_Geeks_ForGeeks Explanation:Class and Object : Person class is defined with attributes s1 and s2, and an object person is created with values "Geeks" fors1 and "ForGeeks" for s2.f-string Formatting: This is used to format and print the string as "Avatar_Geeks_ForGeeks", inserting the values of person.s1and person.s2.Using string.Template classThis is a simpler, safer alternative to str.format(), as it only supports simple placeholder replacements ($variable) and does not evaluate Python expressions. Python from string import Template class Person: def __init__(self, s1, s2): self.s1 = s1 self.s2= s2 # Create a person object person = Person("Geeks", "ForGeeks") # Safe way using string.Template template = Template("Avatar_${s1}_${s2}") a = template.substitute(s1=person.s1, s2=person.s2) print(a) OutputAvatar_Geeks_ForGeeks Explanation:Class and Object:Person class is created with s1 and s2 attributes, and a person object is initialized with "Geeks" and "ForGeeks".Template Substitution:This substitutes ${s1} and ${s2} with the object's attributes. Comment More infoAdvertise with us Next Article Vulnerability in str.format() in Python S Sowmya.L.R Follow Improve Article Tags : Python Programming Language python-string Python-string-functions Practice Tags : python Similar Reads Python Tutorial - Learn Python Programming Language Python is one of the most popular programming languages. Itâs simple to use, packed with features and supported by a wide range of libraries and frameworks. Its clean syntax makes it beginner-friendly. It'sA high-level language, used in web development, data science, automation, AI and more.Known fo 10 min read Python Interview Questions and Answers Python is the most used language in top companies such as Intel, IBM, NASA, Pixar, Netflix, Facebook, JP Morgan Chase, Spotify and many more because of its simplicity and powerful libraries. To crack their Online Assessment and Interview Rounds as a Python developer, we need to master important Pyth 15+ min read Python OOPs Concepts Object Oriented Programming is a fundamental concept in Python, empowering developers to build modular, maintainable, and scalable applications. By understanding the core OOP principles (classes, objects, inheritance, encapsulation, polymorphism, and abstraction), programmers can leverage the full p 11 min read Python Projects - Beginner to Advanced Python is one of the most popular programming languages due to its simplicity, versatility, and supportive community. Whether youâre a beginner eager to learn the basics or an experienced programmer looking to challenge your skills, there are countless Python projects to help you grow.Hereâs a list 10 min read Python Exercise with Practice Questions and Solutions Python Exercise for Beginner: Practice makes perfect in everything, and this is especially true when learning Python. If you're a beginner, regularly practicing Python exercises will build your confidence and sharpen your skills. To help you improve, try these Python exercises with solutions to test 9 min read Python Programs Practice with Python program examples is always a good choice to scale up your logical understanding and programming skills and this article will provide you with the best sets of Python code examples.The below Python section contains a wide collection of Python programming examples. These Python co 11 min read Python Introduction Python was created by Guido van Rossum in 1991 and further developed by the Python Software Foundation. It was designed with focus on code readability and its syntax allows us to express concepts in fewer lines of code.Key Features of PythonPythonâs simple and readable syntax makes it beginner-frien 3 min read Python Data Types Python Data types are the classification or categorization of data items. It represents the kind of value that tells what operations can be performed on a particular data. Since everything is an object in Python programming, Python data types are classes and variables are instances (objects) of thes 9 min read Input and Output in Python Understanding input and output operations is fundamental to Python programming. With the print() function, we can display output in various formats, while the input() function enables interaction with users by gathering input during program execution. Taking input in PythonPython input() function is 8 min read Enumerate() in Python enumerate() function adds a counter to each item in a list or other iterable. It turns the iterable into something we can loop through, where each item comes with its number (starting from 0 by default). We can also turn it into a list of (number, item) pairs using list().Let's look at a simple exam 3 min read Like