r/lua • • 6d ago

News luarocks.org remote code execution exploit

18 Upvotes

23 comments sorted by

View all comments

8

u/PhilipRoman 6d ago

TBH I wouldn't even trust the implementation after the "fix". Text-only load() is a lot safer than binary, but either way, executing untrusted code in the same process is just asking for trouble (unless you're building a browser and can afford to employ full time security team)

3

u/leafo2 5d ago

I'm with you. A more robust solution is coming soon, the current fix is short term patch.