CVE-2026-34444
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-284
Control de acceso incorrecto
Fecha de publicación:
06/04/2026
Última modificación:
07/04/2026
Descripción
*** Pendiente de traducción *** Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
Impacto
Puntuación base 4.0
7.90
Gravedad 4.0
ALTA



