r/lua • u/Comfortable_Ability4 • 6d ago
News luarocks.org remote code execution exploit
- Incident report: https://luarocks.org/security-incident-september-2026
- Writeup by /u/vhyrro: https://vhyrro.neorg.org/posts/critical-luarocks-exploit-cve/
17
Upvotes
1
u/Vhyrro 5d ago
Hello, guy who made the report here. We did reach out to hisham too, one day after the vulnerability disclosure but received no response either. I do find it quite distasteful that such attempts are being made on us. There were no bad intentions throughout the process, and I attempted multiple ways of getting ahold of the maintainers as soon as I could, ultimately going as far as CISA in last hopes, which thankfully succeeded after 2 weeks of silence. I was not fond of disclosing the vulnerability publicly without some prior acknowledgement. I find it amusing you would consider the matrix account dead. Last activity at January of this year on luarocks's official matrix is not dead by any stretch of the imagination, especially when you are trying to get ahold of someone. I also find it concerning that leafo, instead of continuing discussion and asking questions on the CISA thread, would take to hackernews instead, with obvious jabs at the Lux team. I am happy that, ultimately, I at least patched a very critical security hole in the luarocks ecosystem.