Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
LuaJIT in Luaanti 5 allows an attacker to escape the sandbox
CVE-2026-40959
Summary
A security issue in LuaJIT, used in Luaanti 5, allows an attacker to gain unauthorized access. This affects systems that use LuaJIT with Luaanti 5 before version 5.15.2. To fix this, update Luaanti to version 5.15.2 or later.
Original title
Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.
Original description
Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.
nvd CVSS3.1
9.3
Vulnerability type
CWE-829
Published: 16 Apr 2026 · Updated: 16 Apr 2026 · First seen: 16 Apr 2026