It's in their threat model under 'Module injection':
> The mitigation is to maintain secure access permissions on all directories and package files in search path to ensure unprivileged users do not have write access to them.
> The mitigation is to maintain secure access permissions on all directories and package files in search path to ensure unprivileged users do not have write access to them.
Check out the "yes"es in the "fixed" column in comment at https://bugs.python.org/msg85966