Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-1140

NIXPKGS-2026-1140
published on
Permalink CVE-2026-40959
9.3 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
updated 1 week, 5 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    2 packages
    • luanti-client
    • luanti-server
  • @LeSuisse ignored
    3 maintainers
    • @06kellyjac
    • @fpletz
    • @fgaz
    maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Luanti 5 before 5.15.2, when LuaJIT is used, allows a …

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

Affected products

Luanti
  • <5.15.2

Matching in nixpkgs

Ignored packages (2)

Package maintainers

Ignored maintainers (3)