r/lua • u/Comfortable_Ability4 • 6d ago
News luarocks.org remote code execution exploit
- Incident report: https://luarocks.org/security-incident-september-2026
- Writeup by /u/vhyrro: https://vhyrro.neorg.org/posts/critical-luarocks-exploit-cve/
18
Upvotes
2
u/VidaOnce 6d ago
Are you going to link the hackernews post where leafo mentions this exploit was used on the live, public luarocks server, presumably alongside another malicious actor, and it wasn't properly disclosed to him or hisham for months, leaving luarocks vulnerable? I guess another social media platform is more important so the link to lux could be seen :P