Executive brief
Luanti (formerly Minetest), an open-source voxel game engine, contains a vulnerability that allows malicious game modifications (mods) to break out of their restricted security environment. If a user installs a malicious mod, the mod can bypass security controls to execute unauthorized commands and access any file on the user's computer. This could lead to total system compromise, data theft, or the installation of malware.
Technical details
A sandbox escape vulnerability exists in Luanti versions 5.0.0 through 5.15.1 when configured to use LuaJIT. The flaw stems from the inclusion of unsafe functions like 'getfenv' and 'setfenv' in the sandboxed Lua environment (CWE-829), which can be leveraged by a malicious mod to manipulate the execution environment. An attacker can exploit this to escape the Lua sandbox across server-side, client-side (CSM), async, and mapgen environments. Successful exploitation grants the attacker arbitrary code execution and full filesystem access on the host machine. The issue is resolved in version 5.15.2 by sanitizing the environment of safe functions; a workaround involves manually setting 'getfenv = nil' in builtin/init.lua.
Affected products
- Luanti (formerly Minetest) Luanti 5.0.0 through 5.15.1
Timeline
- 2026-03-19: patched: Fix committed to repository
- 2026-04-14: advisory: GitHub Security Advisory published
- 2026-04-16: disclosed: CVE published to NVD