Luarocks.org remote code execution exploit
9 hours ago
- A regular user account could gain root access on luarocks.org via a remote code execution vulnerability.
- The vulnerability exploited Lua's loadstring() function, which accepts both source code and untrusted bytecode.
- The sandbox used setfenv to restrict global functions but did not block malicious bytecode.
- The exploit crafted bytecode using KNUM and ISNEP instructions to read out-of-bounds memory and locate the package.loaded table.
- Using debug.getfenv on a C function, the attacker retrieved the global environment and executed arbitrary Lua code.
- The attack could have enabled supply chain attacks by injecting malware into popular Lua packages like lua-cjson.
- The vulnerability was patched on September 26, 2026.