CVE-2026-34444
Severity CVSS v4.0:
HIGH
Type:
CWE-284
Improper Access Control
Publication date:
06/04/2026
Last modified:
01/05/2026
Description
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
Impact
Base Score 4.0
7.90
Severity 4.0
HIGH
Base Score 3.x
10.00
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:scoder:lupa:*:*:*:*:*:python:*:* | 2.6 (including) |
To consult the complete list of CPE names with products and versions, see this page



