Sensitive data can be printed by exposing all of the locals.
I've encountered one with using psycopg2. It stores database connection strings, and is exposed when there is an uncaught exception.
Proposed Resolution
Allow dict traceback or traceback.SHOW_LOCALS to be configured (currently it is hardcoded)