I'd be extremely impressed if someone actually managed to get RCE out of this, considering you'd only be able to use '0' through '9', or 0x30 through 0x39, in your payload.
On a system without these protection mechanisms it would be a easy win.
Reference: https://haxx.in/posts/numeric-shellcode/
The sprintf is to a temporary buffer that's converted to a PyUnicode object before returning, so subsequent portions of the string are written elsewhere.
https://docs.google.com/presentation/d/19K7SK1L49reoFgjEPKCF...