PT-2026-30661 · Lupa · Lupa

·

CVE-2026-34444

·

Published

2026-04-06

·

Updated

2026-07-13

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lupa versions 2.6 and earlier
Description Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In versions 2.6 and earlier, the attribute filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass intended restrictions and potentially achieve arbitrary code execution.
Recommendations Update to a version of Lupa later than 2.6.

Exploit

Fix

Improper Access Control

IDOR

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34444
GHSA-69V7-XPR6-6GJM
OPENSUSE-SU-2026:10507-1
PYSEC-2026-2613

Affected Products

Lupa