Junglewise Threat Intelligence

CVE-2026-24874: LuaJIT type confusion in lj_debug_getinfo

CVE-2026-24874 · Severity: critical · CVSS 9.1 · Published 2026-01-27

Executive brief

xray-monolith is a toolset that includes a cloned copy of LuaJIT, a just-in-time compiler for the Lua programming language. The application failed to apply a critical security patch from the upstream LuaJIT project, leaving it vulnerable to a type confusion attack that could allow an attacker to read or write memory and potentially execute arbitrary code.

Technical details

This is a type confusion vulnerability in the lj_debug_getinfo() function within the bundled LuaJIT 2 library. The vulnerable code was cloned from LuaJIT but did not receive a security patch (commit c017b2b) that was applied to the upstream repository. The vulnerability allows an attacker to access memory using an incompatible type, potentially leading to memory corruption or code execution. The attack is network-reachable if the application exposes Lua script execution to untrusted input. A patch is available via pull request #399, which applies the same fix from the upstream LuaJIT project.

Affected products

  • themrdemonized xray-monolith before 2025.12.30

Timeline

  • 2026-01-27: disclosed
  • 2025-12-30: patched: Fix merged in PR #399

References