
scoder/lupa
Releases96
Frequency1 month 4 weeks
Last Release
Stars1.14K
Lua in Python
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 10 CRITICAL | — | ||
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution. | |||