CVE-2026-34444: Scoder Lupa
Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
Affected products
- Scoder Lupa: up to and including 2.6
Published 2026-04-06. Last modified 2026-07-15.