CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-34444

Critical · CVSS 10.0

Lupa — Improper Access Control / Attribute Filter Bypass leading to Arbitrary Code Execution

CVSS
10.0
nvd
EPSS
KEV
No
Class
other
CWE-284, CWE-639, CWE-914

Description

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

Search profile — drives PoC discovery

Symbols attribute_filtergetattrsetattrLuaRuntimelua_typepython_evalunpacks_lua_table
Keywords CVE-2026-34444lupa attribute_filter bypasslupa getattr setattr bypasslupa arbitrary code executionGHSA-69v7-xpr6-6gjmlupa LuaJIT2 CPython sandbox escapelupa 2.6 exploitscoder lupa security
Versions: <= 2.6

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z