A proof-of-concept for the 2026 Remote Code Execution vulnerability in luarocks.org
Lua
6
2 commits
updated Sep 27, 2026
luarocks.orgThis repository contains a proof-of-concept for the now-patched sandbox escape that allowed any regular user to gain root privileges on the entire website with a maliciously crafted package upload.
The full writeup can be found here.
The exploit chain works as follows:
luarocks.org accepts bytecode masquerading as a rockspec.KNUM bytecode instruction to read out of memory.ISNEP instruction to safely filter out valid table objects in the out-of-bounds heap.debug field -- usually package.loaded.debug.getfenv(debug.getfenv) to obtain the global environment _G._G.loadstring("malicious code") to run any Lua code as root.exploit.lua -- the bytecode patcher and uploading logic.payload-bootstrap.lua -- the Lua code that gets compiled into bytecode and then patched.payload.lua -- the actual payload that runs on the target machine.nix develophttps://github.com/luarocks/luarocks-site at commit 67c5aa0290198609bde78d5743e8def0d9d66fdddocker build . -t luarocks-sitedocker run --network host luarocks-siteluajit exploit.lua --api-key <your-key> payload.luaLua
95.6%
Nix
4.3%
A proof-of-concept for the 2026 Remote Code Execution vulnerability in luarocks.org
Lua
6
2 commits
updated Sep 27, 2026
luarocks.orgThis repository contains a proof-of-concept for the now-patched sandbox escape that allowed any regular user to gain root privileges on the entire website with a maliciously crafted package upload.
The full writeup can be found here.
The exploit chain works as follows:
luarocks.org accepts bytecode masquerading as a rockspec.KNUM bytecode instruction to read out of memory.ISNEP instruction to safely filter out valid table objects in the out-of-bounds heap.debug field -- usually package.loaded.debug.getfenv(debug.getfenv) to obtain the global environment _G._G.loadstring("malicious code") to run any Lua code as root.exploit.lua -- the bytecode patcher and uploading logic.payload-bootstrap.lua -- the Lua code that gets compiled into bytecode and then patched.payload.lua -- the actual payload that runs on the target machine.nix develophttps://github.com/luarocks/luarocks-site at commit 67c5aa0290198609bde78d5743e8def0d9d66fdddocker build . -t luarocks-sitedocker run --network host luarocks-siteluajit exploit.lua --api-key <your-key> payload.luaLua
95.6%
Nix
4.3%