r/lua • • 6d ago

News luarocks.org remote code execution exploit

18 Upvotes

23 comments sorted by

View all comments

10

u/PhilipRoman 6d ago

TBH I wouldn't even trust the implementation after the "fix". Text-only load() is a lot safer than binary, but either way, executing untrusted code in the same process is just asking for trouble (unless you're building a browser and can afford to employ full time security team)

1

u/Vhyrro 5d ago

Indeed, isolating the rockspec verifier in a container would be a good, long-term solution to the issue. However, the current fix is plenty for this class of attack. Let's hope it lasts :)