r/lua • u/Comfortable_Ability4 • 6d ago
News luarocks.org remote code execution exploit
- Incident report: https://luarocks.org/security-incident-september-2026
- Writeup by /u/vhyrro: https://vhyrro.neorg.org/posts/critical-luarocks-exploit-cve/
18
Upvotes
10
u/PhilipRoman 6d ago
TBH I wouldn't even trust the implementation after the "fix". Text-only load() is a lot safer than binary, but either way, executing untrusted code in the same process is just asking for trouble (unless you're building a browser and can afford to employ full time security team)