CVE-2026-34444: Scoder Lupa

Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

Affected products

  • Scoder Lupa: up to and including 2.6

Published 2026-04-06. Last modified 2026-07-15.