Post

LuaRocks discloses an exploited server-side RCE

LuaRocks says attackers exploited a bytecode-loading flaw in LuaRocks.org from July 9 through August 20, 2026; the fix shipped on September 26, after the vulnerability was reported on September 25. The issue let any registered user upload a rockspec that the server treated as LuaJIT bytecode, escaping the restricted environment and executing arbitrary code.

The project rebuilt and moved the site, revoked old server credentials, and found no evidence that existing packages were modified. It nevertheless treats all data accessible to the compromised server as exposed: users should rotate API keys and passwords, end old sessions, and reset 2FA. Anyone who installed three named malicious packages should treat the machine as compromised; LuaRocks users on LuaJIT or Lua 5.1 should upgrade to 3.12 or newer.

Lobsters commenters focused on the bytecode/text boundary: one argued Lua’s load default should accept text only, while another noted the project sandbox checked source but did not equally constrain bytecode. The post has just two comments, so that is a narrow reaction, not a consensus.