Luarocks.org remote code execution exploit

https://vhyrro.neorg.org/posts/critical-luarocks-exploit-cve/

Comments

rurbanSep 28, 2026, 6:12 AM
Oh oh, unsafe eval in a sandbox! (loadstring).

In my lua-like sandbox I disabled all escape hatches and unsafe functions physically by #ifndef SANDBOX. No IO, no FFI, no byte code loading, no memory funcs and such.

cupcakerobSep 27, 2026, 8:13 PM
[dead]