CVE-2026-34444

Severity CVSS v4.0:
HIGH
Type:
CWE-284 Improper Access Control
Publication date:
06/04/2026
Last modified:
01/05/2026

Description

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:scoder:lupa:*:*:*:*:*:python:*:* 2.6 (including)