CVE-2026-34444
Critical · CVSS 10.0Lupa — Improper Access Control / Attribute Filter Bypass leading to Arbitrary Code Execution
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-284, CWE-639, CWE-914
Description
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
Search profile — drives PoC discovery
Symbols attribute_filtergetattrsetattrLuaRuntimelua_typepython_evalunpacks_lua_table
Keywords CVE-2026-34444lupa attribute_filter bypasslupa getattr setattr bypasslupa arbitrary code executionGHSA-69v7-xpr6-6gjmlupa LuaJIT2 CPython sandbox escapelupa 2.6 exploitscoder lupa security
Versions: <= 2.6
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0redyank/CVE-2026-34444 needs reviewgh_search
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z