Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: python314Packages.lupa

Found 1 matching suggestions

View:
Compact
Detailed
Published
updated 3 weeks, 5 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr

Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.

Affected products

lupa
  • ==<= 2.6

Matching in nixpkgs

Package maintainers