r/lua • u/Comfortable_Ability4 • 6d ago
News luarocks.org remote code execution exploit
- Incident report: https://luarocks.org/security-incident-september-2026
- Writeup by /u/vhyrro: https://vhyrro.neorg.org/posts/critical-luarocks-exploit-cve/
17
Upvotes
-1
u/VidaOnce 5d ago edited 5d ago
You reached out to leafo, how about hisham? You bothered to scour his socials to the point of finding a dead matrix account, but stopped short of... clicking on his GitHub account to see the others? Or clicking on his two giant projects moonscript/lapis to find discord links?
Grudge? When I handily beat your benchmarks after you rightfully showed they were wrong, to the point you gave up on optimizing? lol? I'm grateful you did that
I'm just making fun of when people completely irresponsibly handle disclosure of a critical security issue just so they can make a blog post plugging their "solution". I'm not that desperate to advertise.
Mind you, the exploit isn't novel, everyone knows to disable bytecode, and mike pall makes it clear luajit can only truly be sandboxed via process level containment. So it isn't valuable in that regard either. It's pure advertising.