CVE-2026-34444
EUVD-2026-1934606.04.2026, 16:16
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| scoder | lupa | 𝑥 ≤ 2.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration