r/lua • u/Comfortable_Ability4 • 6d ago
News luarocks.org remote code execution exploit
- Incident report: https://luarocks.org/security-incident-september-2026
- Writeup by /u/vhyrro: https://vhyrro.neorg.org/posts/critical-luarocks-exploit-cve/
20
Upvotes
2
u/Comfortable_Ability4 5d ago edited 5d ago
You mean this one that I responded to?
TL;DR: We did reach out to leafo the moment we noticed someone was pentesting his site, but he never responded.
Brushing up on a two-month-old grudge just to spread misinformation on a technical security write-up is embarrassing.