Vulnerabilities (CVE)

Filtered by vendor Scoder Subscribe
Filtered by product Lupa
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-34444 1 Scoder 1 Lupa 2026-05-01 N/A 10.0 CRITICAL
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.