CVE-2026-40959CRITICAL 9.3EPSS p7.9%

CVE-2026-40959CVE-2026-40959

Description

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

Scoring

CVSS 3.19.3 (CRITICAL)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS0.18% probability of exploitation · percentile 7.9% · 2026-06-19T12:03:05Z
Published2026-04-16
Last modified2026-05-19

Underlying weaknesses· 1

CWE-829

References

  1. https://github.com/luanti-org/luanti/commit/53cef183e2a85a4daff84ac1a9a7946f940da8f8
  2. https://github.com/luanti-org/luanti/commit/8a929dfb97aa08337f49ba1bb96a56d6557dc896
  3. https://github.com/luanti-org/luanti/security/advisories/GHSA-g596-mf82-w8c3

1

TypeTargetConfidenceTier
WeaknessInclusion of Functionality from Untrusted Control Spherecwe-8290%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-40960
CVE
CVE-2026-41196
CVE
Debian-specific Redis Server Lua Sandbox Escape Vulnerability
CVE
CVE-2025-29902
CVE
CVE-2026-25276
CVE
CVE-2026-5752
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.