Junglewise Threat Intelligence

CVE-2026-41196: Luanti Lua sandbox escape via LuaJIT environment manipulation

CVE-2026-41196 · Severity: critical · CVSS 10 · Published 2026-04-23

Executive brief

Luanti (formerly Minetest) is an open-source voxel game-creation platform. A critical security flaw allows malicious game modifications (mods) to bypass security restrictions and run unauthorized code on a user's computer or server. This could lead to full control over the device, including the ability to steal or delete files and disrupt operations.

Technical details

A sandbox escape vulnerability exists in Luanti's Lua environment when using LuaJIT. The flaw allows a malicious mod to bypass the intended restrictions of the Lua sandbox, affecting server-side, client-side (CSM), async, and mapgen environments. By escaping the sandbox, an attacker can achieve arbitrary code execution (ACE) and full filesystem access on the host machine. The root cause is related to the availability of certain Lua functions like 'getfenv' and 'setfenv' which were not properly sanitized or restricted. The issue is fixed in version 5.15.2; a manual workaround involves setting 'getfenv = nil' in 'builtin/init.lua'.

Affected products

  • Luanti Luanti (formerly Minetest) 5.0.0 to 5.15.1

Timeline

  • 2026-03-19: patched: Fix committed to repository
  • 2026-04-14: advisory: GitHub security advisory published
  • 2026-04-23: disclosed: CVE published to NVD

References

Related threats