Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34444

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

A flaw was found in Lupa, a tool that integrates Lua or LuaJIT2 runtimes into CPython. An attacker can exploit this vulnerability by bypassing attribute filtering mechanisms when accessing attributes through built-in functions like getattr and setattr. This inconsistency in applying security restrictions can allow an attacker to execute arbitrary code, potentially compromising the system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-914
https://bugzilla.redhat.com/show_bug.cgi?id=2455413lupa: Lupa: Arbitrary Code Execution due to inconsistent attribute filtering

EPSS

Процентиль: 46%
0.00613
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 10
ubuntu
4 месяца назад

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

CVSS3: 10
nvd
4 месяца назад

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

CVSS3: 10
debian
4 месяца назад

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 an ...

CVSS3: 10
github
4 месяца назад

Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

EPSS

Процентиль: 46%
0.00613
Низкий

8.1 High

CVSS3

Уязвимость CVE-2026-34444