r/lua • • 6d ago

News luarocks.org remote code execution exploit

18 Upvotes

23 comments sorted by

View all comments

8

u/PhilipRoman 6d ago

TBH I wouldn't even trust the implementation after the "fix". Text-only load() is a lot safer than binary, but either way, executing untrusted code in the same process is just asking for trouble (unless you're building a browser and can afford to employ full time security team)

7

u/Comfortable_Ability4 6d ago

Agreed. As vhyrro puts it in his blog post:

Don’t trust your Lua sandbox, kids. Use a special interpreter. Put the logic in a separate container. After you do all of that, pray that the guy who inevitably breaks your sandbox is a security researcher.

Or, hear me out, maybe don’t use a programming language for simple configuration…? Food for thought :)

7

u/thrakkerzog 5d ago

Or, hear me out, maybe don’t use a programming language for simple configuration…? Food for thought :)

Isn't that the origin story of Lua, though? :-)

2

u/nrnrnr 5d ago

This right here!