CVE-2026-34444: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34444 is a sandbox escape and remote code execution vulnerability in Lupa, a Python library that integrates Lua and LuaJIT2 runtimes into CPython. The flaw affects Lupa versions 2.6 and earlier, where the attribute_filter security mechanism is not consistently enforced when Python attributes are accessed via built-in functions getattr and setattr, allowing attackers to bypass intended restrictions and achieve arbitrary code execution. It was published on April 5–6, 2026, with a CVSS v3.1 base score of 10.0 (Critical) and a CVSS v4.0 base score of 7.9 (High) (Github Advisory, Red Hat Bugzilla). IBM Cloud Pak for AIOps is also listed as an affected product (IBM Advisory).

Technical details

The root cause is improper access control (CWE-284) and protection mechanism failure (CWE-693): Lupa's attribute_filter is applied only to direct attribute access (obj.attr) but is bypassed entirely when Lua code uses Python's built-in getattr and setattr functions via python.builtins. This inconsistency allows an attacker with the ability to execute Lua code — and access to Python builtins — to traverse the Python object graph by accessing __class__, walking the __mro__ chain, calling __subclasses__(), and ultimately retrieving execution primitives such as os.system. The attack requires no authentication and no user interaction, but does require that the application grants Lua code access to Python builtins (i.e., does not use register_builtins=False). A complete proof-of-concept Python script demonstrating the sandbox escape is publicly available in the official security advisory (Github Advisory).

Impact

Successful exploitation results in full sandbox escape and arbitrary command execution within the host Python process, with high impact to confidentiality, integrity, and availability of the subsequent (host) system. An attacker can execute arbitrary OS commands (e.g., os.system('id')), access sensitive data, modify system state, or disrupt service availability. Any application relying on attribute_filter as a security boundary for untrusted Lua code execution is fully compromised if Python builtins are accessible to Lua (Github Advisory, Red Hat Bugzilla).

Exploitability

A functional proof-of-concept exploit (a complete, runnable Python script) is publicly available in the official Lupa security advisory on GitHub, demonstrating RCE via the getattr/setattr bypass (Github Advisory). A separate GitHub repository (redyank/CVE-2026-34444) exists but contains only a README with no actual exploit code. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.049% (16th percentile), indicating a currently low probability of exploitation in the next 30 days. The vulnerability is not listed in the CISA KEV catalog as of the time of this report (Feedly).

Exploitation steps

  1. Identify a target application: Find an application that uses Lupa ≤ 2.6 with an attribute_filter configured to block access to dunder attributes (e.g., those starting with _), but which still grants Lua code access to Python builtins (i.e., register_builtins=True, the default).
  2. Obtain Lua code execution: Leverage any mechanism that allows submitting or injecting Lua code into the target application's LuaRuntime (e.g., a user-supplied script, a template engine, or an API endpoint).
  3. Access Python builtins from Lua: In the Lua payload, retrieve the Python builtins via local py = python.builtins and extract getattr and setattr references.
  4. Bypass the attribute_filter: Use getattr(user, "__class__") to access the class of an exposed Python object — this call bypasses the filter that would block user.__class__ via direct access.
  5. Traverse the MRO chain: Call getattr(cls, "__mro__") to retrieve the method resolution order, then access the base object class.
  6. Enumerate subclasses: Call getattr(obj_cls, "__subclasses__")() to get all subclasses of object and iterate over them.
  7. Find a class with __globals__: Search for a class such as os._wrap_close whose __init__.__globals__ exposes the os module's namespace.
  8. Retrieve and execute os.system: Extract system from the globals dict, assign it to the exposed object via setattr(user, 'run', system), then call user.run('id') (or any arbitrary command) to achieve RCE in the host Python process (Github Advisory).

Indicators of compromise

  • Logs: Application logs showing Lua code execution containing strings such as python.builtins, getattr, setattr, __class__, __mro__, __subclasses__, __globals__, or os._wrap_close; unexpected OS command output (e.g., uid=, gid=) appearing in application output or logs.
  • Process: Unusual child processes spawned by the Python interpreter running Lupa (e.g., /bin/sh, id, whoami, curl, wget, bash) that are not part of normal application behavior.
  • Network: Unexpected outbound network connections from the Python application process to external IPs, potentially indicating reverse shell or data exfiltration activity following exploitation.
  • File System: New or modified files in the application directory or temp directories created by the Python process, such as web shells, scripts, or downloaded payloads (Github Advisory).

Mitigation and workarounds

No patched version of Lupa has been released as of the advisory publication date (all versions ≤ 2.6 are affected, and no patched version is listed). The primary workaround is to instantiate LuaRuntime with register_builtins=False, which prevents Lua code from accessing Python's built-in functions and eliminates the attack vector. Additionally, organizations should implement network-level access controls to restrict which clients can submit Lua code to applications using Lupa, and monitor for exploitation attempts using the published PoC. IBM has released an advisory for Cloud Pak for AIOps users (IBM Advisory), and Red Hat has issued an errata (Red Hat Errata). OpenSUSE has also issued a security announcement (OpenSUSE).

Community reactions

The vulnerability was reported by researcher redyank and disclosed via the official Lupa GitHub security advisory by maintainer scoder on April 5, 2026 (Github Advisory). Red Hat tracked the issue via Bugzilla and assigned it high severity (Red Hat Bugzilla). A blog post titled "Lua in Python Sandbox Escape You Need to Know" was published shortly after disclosure, indicating community interest in the sandbox escape technique (Feedly). No major vendor statements beyond Red Hat and IBM have been identified.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

python-lupa

Affected

sid

python-lupa

Affected

trixie

python-lupa

Affected

Ubuntu

Unknown

bionic (esm-apps)

python-lupa

Unknown

devel

python-lupa

Unknown

focal (esm-apps)

python-lupa

Unknown

jammy

python-lupa

Unknown

jammy (esm-apps)

python-lupa

Unknown

noble

python-lupa

Unknown

noble (esm-apps)

python-lupa

Unknown

resolute

python-lupa

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management