
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34444 is a sandbox escape and remote code execution vulnerability in Lupa, a Python library that integrates Lua and LuaJIT2 runtimes into CPython. The flaw affects Lupa versions 2.6 and earlier, where the attribute_filter security mechanism is not consistently enforced when Python attributes are accessed via built-in functions getattr and setattr, allowing attackers to bypass intended restrictions and achieve arbitrary code execution. It was published on April 5–6, 2026, with a CVSS v3.1 base score of 10.0 (Critical) and a CVSS v4.0 base score of 7.9 (High) (Github Advisory, Red Hat Bugzilla). IBM Cloud Pak for AIOps is also listed as an affected product (IBM Advisory).
The root cause is improper access control (CWE-284) and protection mechanism failure (CWE-693): Lupa's attribute_filter is applied only to direct attribute access (obj.attr) but is bypassed entirely when Lua code uses Python's built-in getattr and setattr functions via python.builtins. This inconsistency allows an attacker with the ability to execute Lua code — and access to Python builtins — to traverse the Python object graph by accessing __class__, walking the __mro__ chain, calling __subclasses__(), and ultimately retrieving execution primitives such as os.system. The attack requires no authentication and no user interaction, but does require that the application grants Lua code access to Python builtins (i.e., does not use register_builtins=False). A complete proof-of-concept Python script demonstrating the sandbox escape is publicly available in the official security advisory (Github Advisory).
Successful exploitation results in full sandbox escape and arbitrary command execution within the host Python process, with high impact to confidentiality, integrity, and availability of the subsequent (host) system. An attacker can execute arbitrary OS commands (e.g., os.system('id')), access sensitive data, modify system state, or disrupt service availability. Any application relying on attribute_filter as a security boundary for untrusted Lua code execution is fully compromised if Python builtins are accessible to Lua (Github Advisory, Red Hat Bugzilla).
A functional proof-of-concept exploit (a complete, runnable Python script) is publicly available in the official Lupa security advisory on GitHub, demonstrating RCE via the getattr/setattr bypass (Github Advisory). A separate GitHub repository (redyank/CVE-2026-34444) exists but contains only a README with no actual exploit code. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.049% (16th percentile), indicating a currently low probability of exploitation in the next 30 days. The vulnerability is not listed in the CISA KEV catalog as of the time of this report (Feedly).
attribute_filter configured to block access to dunder attributes (e.g., those starting with _), but which still grants Lua code access to Python builtins (i.e., register_builtins=True, the default).LuaRuntime (e.g., a user-supplied script, a template engine, or an API endpoint).local py = python.builtins and extract getattr and setattr references.getattr(user, "__class__") to access the class of an exposed Python object — this call bypasses the filter that would block user.__class__ via direct access.getattr(cls, "__mro__") to retrieve the method resolution order, then access the base object class.getattr(obj_cls, "__subclasses__")() to get all subclasses of object and iterate over them.__globals__: Search for a class such as os._wrap_close whose __init__.__globals__ exposes the os module's namespace.os.system: Extract system from the globals dict, assign it to the exposed object via setattr(user, 'run', system), then call user.run('id') (or any arbitrary command) to achieve RCE in the host Python process (Github Advisory).python.builtins, getattr, setattr, __class__, __mro__, __subclasses__, __globals__, or os._wrap_close; unexpected OS command output (e.g., uid=, gid=) appearing in application output or logs./bin/sh, id, whoami, curl, wget, bash) that are not part of normal application behavior.No patched version of Lupa has been released as of the advisory publication date (all versions ≤ 2.6 are affected, and no patched version is listed). The primary workaround is to instantiate LuaRuntime with register_builtins=False, which prevents Lua code from accessing Python's built-in functions and eliminates the attack vector. Additionally, organizations should implement network-level access controls to restrict which clients can submit Lua code to applications using Lupa, and monitor for exploitation attempts using the published PoC. IBM has released an advisory for Cloud Pak for AIOps users (IBM Advisory), and Red Hat has issued an errata (Red Hat Errata). OpenSUSE has also issued a security announcement (OpenSUSE).
The vulnerability was reported by researcher redyank and disclosed via the official Lupa GitHub security advisory by maintainer scoder on April 5, 2026 (Github Advisory). Red Hat tracked the issue via Bugzilla and assigned it high severity (Red Hat Bugzilla). A blog post titled "Lua in Python Sandbox Escape You Need to Know" was published shortly after disclosure, indicating community interest in the sandbox escape technique (Feedly). No major vendor statements beyond Red Hat and IBM have been identified.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
python-lupa
devel
python-lupa
focal (esm-apps)
python-lupa
jammy
python-lupa
jammy (esm-apps)
python-lupa
noble
python-lupa
noble (esm-apps)
python-lupa
resolute
python-lupa
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."