Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-34444

Опубликовано: 06 апр. 2026
Источник: debian
EPSS Низкий

Описание

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-lupaunfixedpackage
python-lupano-dsatrixiepackage
python-lupano-dsabookwormpackage
python-lupapostponedbullseyepackage

Примечания

  • https://github.com/scoder/lupa/security/advisories/GHSA-69v7-xpr6-6gjm

EPSS

Процентиль: 46%
0.00613
Низкий

Связанные уязвимости

CVSS3: 10
ubuntu
4 месяца назад

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

CVSS3: 8.1
redhat
4 месяца назад

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

CVSS3: 10
nvd
4 месяца назад

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

CVSS3: 10
github
4 месяца назад

Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

EPSS

Процентиль: 46%
0.00613
Низкий