CVE-2026-34444
HIGHLupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
Title source: cnaDescription
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
Exploits (1)
Scores
CVSS v4
7.9
EPSS
0.0003
EPSS Percentile
8.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-284
CWE-639
Status
published
Products (2)
pypi/lupa
0PyPI
scoder/lupa
<= 2.6
Published
Apr 06, 2026
Tracked Since
Apr 06, 2026