{"id":"CVE-2026-34444","aliases":["GHSA-69v7-xpr6-6gjm","PYSEC-2026-2613"],"url":"https://o3.security/vulnerability/CVE-2026-34444","summary":"Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr","details":"Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.","published":"2026-04-06T15:30:30.525Z","modified":"2026-07-16T03:31:05.948113549Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"lupa","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34444.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22993"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-34444"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34444.json"},{"type":"ADVISORY","url":"https://github.com/scoder/lupa/security/advisories/GHSA-69v7-xpr6-6gjm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34444"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2455413"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-16T03:31:05.948113549Z"}}