Hasty Briefsbeta

双语

Luarocks.org remote code execution exploit

9 hours ago
  • A regular user account could gain root access on luarocks.org via a remote code execution vulnerability.
  • The vulnerability exploited Lua's loadstring() function, which accepts both source code and untrusted bytecode.
  • The sandbox used setfenv to restrict global functions but did not block malicious bytecode.
  • The exploit crafted bytecode using KNUM and ISNEP instructions to read out-of-bounds memory and locate the package.loaded table.
  • Using debug.getfenv on a C function, the attacker retrieved the global environment and executed arbitrary Lua code.
  • The attack could have enabled supply chain attacks by injecting malware into popular Lua packages like lua-cjson.
  • The vulnerability was patched on September 26, 2026.