CVE-2026-34444

CRITICAL

Lupa <=2.6 getattr and setattr - Sandbox Escape

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-34444. PoCs published by redyank.

AI-analyzed exploit summary The repository contains only a minimal README with a CVE description and no exploit code or technical details. It lacks any functional PoC, analysis, or additional context.

Description

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

Exploits (1)

nomisec STUB
by redyank · poc
https://github.com/redyank/CVE-2026-34444

The repository contains only a minimal README with a CVE description and no exploit code or technical details. It lacks any functional PoC, analysis, or additional context.

Classification
Stub 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unspecified
No auth needed
devstral-2 · analyzed Apr 28, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 10.0
EPSS 0.0052
EPSS Percentile 39.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-639
Status published
Products (3)
pypi/lupa 0 - 2.6PyPI
scoder/lupa < 2.6
scoder/lupa <= 2.6
Published Apr 06, 2026
Tracked Since Apr 06, 2026