Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34444

Опубликовано: 06 апр. 2026
Источник: nvd
CVSS3: 10
EPSS Низкий

Описание

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:scoder:lupa:*:*:*:*:*:python:*:*
Версия до 2.6 (включая)

EPSS

Процентиль: 40%
0.00515
Низкий

10 Critical

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 10
ubuntu
4 месяца назад

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

CVSS3: 8.1
redhat
4 месяца назад

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

CVSS3: 10
debian
4 месяца назад

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 an ...

CVSS3: 10
github
4 месяца назад

Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

EPSS

Процентиль: 40%
0.00515
Низкий

10 Critical

CVSS3

Дефекты

CWE-284