CVE-2026-41196CRITICAL 10.0EPSS p29.1%

CVE-2026-41196CVE-2026-41196

Description

Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to execute arbitrary code and gain full filesystem access on the user's device. This applies to the server-side mod, async and mapgen as well as the client-side (CSM) environments. This vulnerability is only exploitable when using LuaJIT. Version 5.15.2 contains a patch. On release versions, one can also patch this issue without recompiling by editing `builtin/init.lua` and adding the line `getfenv = nil` at the end. Note that this will break mods relying on this function (which is not inherently unsafe).

Scoring

CVSS 3.110.0 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS0.37% probability of exploitation · percentile 29.1% · 2026-06-19T12:03:05Z
Published2026-04-23
Last modified2026-05-14

Underlying weaknesses· 1

CWE-94

References

  1. https://github.com/luanti-org/luanti/commit/8a929dfb97aa08337f49ba1bb96a56d6557dc896
  2. https://github.com/luanti-org/luanti/security/advisories/GHSA-g596-mf82-w8c3

1

TypeTargetConfidenceTier
WeaknessImproper Control of Generation of Code ('Code Injection')cwe-940%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-40959
CVE
CVE-2026-40960
CVE
CVE-2026-34078
CVE
CVE-2026-35093
CVE
CVE-2026-44450
CVE
CVE-2026-5752
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.