Vulnerability Description
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Scoder | Lupa | <= 2.6 |
Related Weaknesses (CWE)
References
- https://github.com/scoder/lupa/security/advisories/GHSA-69v7-xpr6-6gjmExploitVendor Advisory
FAQ
What is CVE-2026-34444?
CVE-2026-34444 is a vulnerability with a CVSS score of 10.0 (CRITICAL). Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and s...
How severe is CVE-2026-34444?
CVE-2026-34444 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-34444?
Check the references section above for vendor advisories and patch information. Affected products include: Scoder Lupa.