CVE-2026-34444
CRITICALLupa <=2.6 getattr and setattr - Sandbox Escape
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2026-34444. PoCs published by redyank.
AI-analyzed exploit summary The repository contains only a minimal README with a CVE description and no exploit code or technical details. It lacks any functional PoC, analysis, or additional context.
Description
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
Exploits (1)
The repository contains only a minimal README with a CVE description and no exploit code or technical details. It lacks any functional PoC, analysis, or additional context.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H