VULNERABILITY OVERVIEW CVE-2026-34444 affects Lupa version 2.6 and earlier, a Python library that integrates Lua and LuaJIT2 runtimes into CPython. The vulnerability stems from inconsistent application of the attribute_filter security control when attributes are accessed through built-in functions such as getattr and setattr, enabling attackers to circumvent intended access restrictions. SEVERITY ASSESSMENT The vulnerability permits arbitrary code execution through attribute filter bypass, representing a critical impact potential. While specific CVSS vector details are unavailable, the EPSS score of 0.00028 and FAUCET Risk Score of 49.0/100 indicate moderate community concern. The attack requires local access and understanding of the Lupa library's implementation, suggesting moderate attack complexity rather than trivial exploitation. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat tracking lists. However, the availability of descriptive technical information regarding the attribute_filter bypass mechanism may facilitate exploit development by motivated threat actors familiar with Python and Lua integration mechanisms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6CPE matchmatch criteria | cpe:2.3:a:scoder:lupa:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.