It's sort of the same as #946373, except that bug report deals with other bad consequences of sys.path[0], unrelated to security.

#5753 is specifically about the C API, not about running "plain" Python.
