CVE-2026-34444Disclosure(scoder / lupa)

MEDIUMCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch scoder lupa systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-639CWE-914

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lupa

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-12)
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
lupa

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-04-06: 2Mentions · 2026-04-07: 1Mentions · 2026-04-09: 1Mentions · 2026-05-01: 1Mentions · 2026-05-12: 3PoC Mentioned / Linked · 2026-04-09: 1Exploit Tool / Code · 2026-04-09: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-06: 2Technical Details · 2026-04-07: 1Technical Details · 2026-04-09: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-12: 204-0604-0704-0905-0105-12
Signal classification3 categories
Disclosure
450.0%
General
225.0%
Patch
225.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-062
Disclosure2
2026-04-071
General1
2026-04-091
Patch1
2026-05-011
Patch1
2026-05-123
Disclosure2General1
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 10 CRITICAL · CVE-2026-34444 · 2.6 → 3.1 CVE: CVE-2026-34444 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    This is an advisory for CVE-2026-34444, stating it is critical with a CVSS score of 10, without additional exploit, patch, or active exploitation information.

    1000040
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-34444 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Lupa integrates the runtimes of Lua or LuaJIT2 into CPython.

    Post summary

    The advisory announces CVE‑2026‑34444 as a critical vulnerability in Lupa's Lua runtime integration with CPython, including a CVSS 10 score and severity rating, but does not disclose exploits, patches, or PoCs.

    1000029
    210 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🐍 Lua in Python? Yes, and it's broken. CVE-2026-34444 lets attackers bypass attribute_filter via getattr to run shell commands. Patch lupa to >2.8 NOW. Full lab + script below. Read more: 👉 https://tinyurl.com/2e7cr57b https://t.co/fCxYoYt3lN

    Post summary

    The post highlights CVE‑2026‑34444, explains it lets Lua in Python bypass attribute filtering to run shell commands, shares a proof‑of‑concept script, and urges users to patch Lupa to version >2.8.

    0001070
    1.5K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-34444-scoder-lupa #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The message is a link to research about CVE-2026-34444, but no substantive details, PoC, or exploit information are included.

    0000026
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Defenders must prioritize patching CVE-2026-34444 to prevent arbitrary code execution in vulnerable apps. Exploitability through built-in functions heightens risk significantly. Full analysis: https://research.lyrie.ai/research/cve-2026-34444-scoder-lupa

    Post summary

    The post urges prompt patching of CVE-2026-34444 to prevent arbitrary code execution, but does not provide a PoC, exploit tool, or evidence of active exploitation.

    0000044
    152 followersView on X
  • DailyCVE@dailycve
    General

    🔴 Lupa (#Python-Lupa), Attribute Filter Bypass, #CVE-2026-34444 (Critical) https://dailycve.com/lupa-python-lupa-attribute-filter-bypass-cve-2026-34444-critical/

    Post summary

    The tweet announces a new critical CVE-2026-34444 in Lupa, describing an attribute filter bypass, but provides no PoC, exploit code, patch details, or evidence of active exploitation.

    0000032
    178 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34444 Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through bui… https://www.cve.org/CVERecord?id=CVE-2026-34444 ----- Traducción: CVE-2026-34444 Lup… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑34444, describing a flaw in Lupa’s handling of Lua runtimes in older CPython versions, with a link to the official CVE record for details.

    0000036
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34444 Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through bui… https://www.cve.org/CVERecord?id=CVE-2026-34444

    Post summary

    The text announces CVE-2026-34444, noting a flaw in Lupa’s integration of Lua runtimes where attribute filtering is inconsistently applied in CPython, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000177
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appscoderlupa-python-

Explore more