Back to CVE List

CVE-2026-34444

HIGH SEVERITY

Vulnerability Description

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-284
Source
NVD
Vendor
scoder
Product
lupa

External References

Discussion (0)

Add Comment

No comments yet. Be the first!