VYPR
Critical severity10.0NVD Advisory· Published Apr 6, 2026· Updated May 1, 2026

CVE-2026-34444

CVE-2026-34444

Description

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
lupaPyPI
<= 2.6

Affected products

1
  • cpe:2.3:a:scoder:lupa:*:*:*:*:*:python:*:*
    Range: <=2.6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.