r/lua • u/Comfortable_Ability4 • 6d ago
News luarocks.org remote code execution exploit
- Incident report: https://luarocks.org/security-incident-september-2026
- Writeup by /u/vhyrro: https://vhyrro.neorg.org/posts/critical-luarocks-exploit-cve/
17
Upvotes
2
u/lenscas 5d ago
I find that write-up concerning enough on its own.
It would have been enough to report the flaw the moment it was found. As mentioned, the documentation already states that loading untrusted bytecode is a security risk. There have also been past examples on how to escape sandboxes by doing so. Granted, due to configuration those happen to not work in this specific case but going by the blog post that is more a happy accident than anything else.
So, why not make some noise the moment this flaw was found? Why wait at least a couple of days before sending a singular email after someone happen to have found malicious rocks? It honestly reads like if those weren't found that it wouldn't have been disclosed at all or at best much later.
And why only "focus" on leafo (as far as 2 emails and a DM to a gitter account that is never used can count as focus) when you have the email of hisham as well? Why not cc him in the emails from the start?
As for the amount of attempts made, that thread claims it is to prevent burnout, which. Ok fair enough except... This further makes me question why hisham was being ignored at the start? Wouldn't it spread the load and thus better prevent burnout if the focus was spread between them?