Rendered at 23:45:22 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
xx_ns 15 hours ago [-]
Very good write up! Kudos.
I recently wrote about an RCE exploit in the game Project Zomboid (which uses Lua for mods), which also used loadstring as an initial entry point for the exploit chain, but since the Lua interpreter was fully Java, byte-code memory manipulation shenanigans were out of the question for me and I had to pivot in a more traditional way.
The fact that loadstring can also load straight up bytecode was news to me though, that's interesting to know.
Natfan 14 hours ago [-]
any further information on this PZ RCE? as a casual player i'm somewhat interested -- did the vulnerability get patched?
They were very fast to patch it. The patch actually removed loadstring (among the other fixes), which broke a bunch of mods for a while. The vulns themselves could also theoretically be abused by malicious mods, which unfortunately seems to be more commonplace these days.
leafo 4 hours ago [-]
In my opinion, this is a terrible display of "ethical" reporting.
For context, I built and run the luarocks.org website. It's very easy to see I run the website, and find my contact information. I appreciate that they eventually shared the exploit but...
* They sat on this vulnerability for over a month, likely trying to figure out how to fully exploit it, instead of reporting it. (I would imagine their ai agent upon seeing the `loadstring` issue told them "go tell the maintainer immediately", which they ignored)
* They finally reported it through an intermediate, CISA.gov, and never contacted me directly. When CISA eventually reached out to me, it took multiple days for me to get approved to view the report.
* When I got access to the report I stayed up all night doing deep investigation of logs, all packages and doing the server rebuild. I published the security bulletin on the luarocks.org website (https://luarocks.org/security-incident-september-2026) as soon as the server was rebuilt. They saw it and had time to write up this entire dramatized blog post but still haven't contacted me. (I asked for a follow-up through CISA, but I don't know how long those exchanges take.)
* The vulnerability was exploited on production luarocks.org during that time by them, and they failed to mention any production testing in any of their reports, both in the blog post and in the CISA.gov report.
* They position themselves as members of the Lua community, running alternative Lua runtimes and a new Lua package manager, yet they sat on a very critical issue that affected much of the Lua community for an extended period of time.
* Update: they replied to me on CISA, acknowledging that they exercised the exploit on the production server. (This is still not disclosed anywhere) They said they only did a "sleep" test, but our server logs contradict their attempts based on the accounts they revealed to be as part of their testing.
I get it, you found an exploit and you want credit for your hacking skills, but this whole exchange has really rubbed me the wrong way. Since they haven't told me what malicious code they ran on the production server, or verified what accounts they used to exploit the sever on production, it wastes my time when I'm doing forensics to analyze the extent of what happened to make the appropriate decisions incident response.
In the current era of LLM coding, anyone can vibe code a new Luarocks in Rust (or whatever is popular) over a weekend. I think that establishing trust is more important than ever, and this interaction just makes me question the maintainers of Lux. Their own self-interest appears to be above whatever they are trying to do for the Lua community at large.
mrcjkb 2 hours ago [-]
I maintain Lux with Vhyrro and feel I should clarify what actually happened here...
I’ve gone through our archived Matrix chat history to clear up the timeline.
On August 7th, Vhyrro messaged me after noticing someone had uploaded malicious rockspecs, `bcrcewon-1.0.rockspec` and `7e0b94029db0`, to luarocks.org.
I suggested we notify you and Hisham and gave him Hisham's e-mail address (which I had in my address book, since I had been in touch with him before and based on prior experience knew you were hard to reach).
Vhyrro found your Gmail address and sent you an email on August 7th:
---
> I've noticed that somebody on luarocks.org has uploaded two potentially malicious rockspecs: [...]
These two packages contain luajit bytecode instead of traditional Lua code, which means they could contain some sort of sandbox escape and could have done some damage on the actual server itself, and may be worth investigating.
Coincidentally, I've been researching this exploit vector myself over the past week, but in isolation and on my local docker run of luarocks-site. It's entirely plausible that luajit bytecode has some out-of-bounds read or write which could spell trouble for the real site, which is why I am writing you with such concern. I haven't dissected the bytecode yet, and so I can't test if it works, but it might be worth preemptively rolling out a fix. Maybe a check that disallows bytecode uploads?
Seeing someone attempt a similar thing on the main luarocks site is not good news, so I recommend having a look on the main server to see if anything got compromised.
---
On August 14th, Vhyrro told me he had achieved full RCE (reproduced locally on his docker instance).
He spent the next day cleaning up his POC to make it consistently reproducible.
On August 15th, he sent you a second follow-up email to your Gmail address.
We agreed to wait for a response for 2 weeks and then look for alternate channels to reach you on.
On August 16th, he told me he was considering messaging Hisham because his previous email to you about the guy pentesting your site had gone unanswered.
A day later, Vhyrro again asked me if we should try reaching out to you on other channels.
I urged him to give it some time because we know you & Hisham maintain LuaRocks in your free time,
and we don't want to contribute to FOSS maintainer burnout.
On August 20th, we joined the official luarocks matrix room (#luarocks_luarocks:gitter.im) and found your personal Matrix handle.
That's when Vhyrro DM'd you on Matrix.
Finally, on September 10th, over a month after his initial warning about the live attack and weeks after his follow-ups regarding the RCE PoC,
having received no response across email or Matrix, Vhyrro submitted the report to CERT/CC.
Regarding your comment on Lux: Dismissing our work as LLM "vibe coding" (it's not) and claiming we acted out of self-interest is an unfair personal attack.
We did all we could to try and warn you early while giving you enough time to address a severe issue without causing unnecessary panic.
leafo 1 hours ago [-]
> Vhyrro found your Gmail address and sent you an email on August 7th:
I just searched my email and found nothing. Do you have subject line, sender address or receipt or anything that would help me find the emails that were sent?
> found your personal Matrix handle. That's when Vhyrro DM'd you on Matrix.
I don't use Matrix. There's a gitter.im for Luarocks that's effectively dead. I last was there in January 2026 asking if the server was alive but never returned. I logged into gitter right now to check and I was able to find a DM request from August 20th, I wouldn't have seen this under any normal circumstances though
Well, thanks for sharing you attempted to contact me at least.
mrcjkb 1 hours ago [-]
I don't have the exact subject line, but I assume Vhyrro used his email address that is linked on his web page.
He initially tried contacting you via the e-mail address listed in https://github.com/luarocks/luarocks/blob/1c9266d6521c16e126....
Have you checked your junk folder?
leafo 58 minutes ago [-]
Yes, I did thorough scan of my email, with Vhyrro's email, name and other keywords related to luarocks. Nothing was found. I asked Hisham to take a look for an email as well.
mrcjkb 39 minutes ago [-]
I guess if they did land in your junk folder, Gmail may have purged them automatically after 30 days.
After not receiving an email response, Vhyrro asked in a group chat if there was any direct line of contact with you or Hisham that wasn't email. That's when someone gave us the luarocks gitter link. Apart from that, we couldn't find any alternative way of reaching you.
rurban 18 hours ago [-]
Oh oh, unsafe eval in a sandbox! (loadstring).
In my lua-like sandbox I disabled all escape hatches and unsafe functions physically by #ifndef SANDBOX. No IO, no FFI, no byte code loading, no memory funcs and such.
I recently wrote about an RCE exploit in the game Project Zomboid (which uses Lua for mods), which also used loadstring as an initial entry point for the exploit chain, but since the Lua interpreter was fully Java, byte-code memory manipulation shenanigans were out of the question for me and I had to pivot in a more traditional way.
The fact that loadstring can also load straight up bytecode was news to me though, that's interesting to know.
e: https://blog.nns.ee/2026/08/26/project-zomboid-vulns/
They were very fast to patch it. The patch actually removed loadstring (among the other fixes), which broke a bunch of mods for a while. The vulns themselves could also theoretically be abused by malicious mods, which unfortunately seems to be more commonplace these days.
For context, I built and run the luarocks.org website. It's very easy to see I run the website, and find my contact information. I appreciate that they eventually shared the exploit but...
* They sat on this vulnerability for over a month, likely trying to figure out how to fully exploit it, instead of reporting it. (I would imagine their ai agent upon seeing the `loadstring` issue told them "go tell the maintainer immediately", which they ignored)
* They finally reported it through an intermediate, CISA.gov, and never contacted me directly. When CISA eventually reached out to me, it took multiple days for me to get approved to view the report.
* When I got access to the report I stayed up all night doing deep investigation of logs, all packages and doing the server rebuild. I published the security bulletin on the luarocks.org website (https://luarocks.org/security-incident-september-2026) as soon as the server was rebuilt. They saw it and had time to write up this entire dramatized blog post but still haven't contacted me. (I asked for a follow-up through CISA, but I don't know how long those exchanges take.)
* The vulnerability was exploited on production luarocks.org during that time by them, and they failed to mention any production testing in any of their reports, both in the blog post and in the CISA.gov report.
* They position themselves as members of the Lua community, running alternative Lua runtimes and a new Lua package manager, yet they sat on a very critical issue that affected much of the Lua community for an extended period of time.
* Update: they replied to me on CISA, acknowledging that they exercised the exploit on the production server. (This is still not disclosed anywhere) They said they only did a "sleep" test, but our server logs contradict their attempts based on the accounts they revealed to be as part of their testing.
I get it, you found an exploit and you want credit for your hacking skills, but this whole exchange has really rubbed me the wrong way. Since they haven't told me what malicious code they ran on the production server, or verified what accounts they used to exploit the sever on production, it wastes my time when I'm doing forensics to analyze the extent of what happened to make the appropriate decisions incident response.
In the current era of LLM coding, anyone can vibe code a new Luarocks in Rust (or whatever is popular) over a weekend. I think that establishing trust is more important than ever, and this interaction just makes me question the maintainers of Lux. Their own self-interest appears to be above whatever they are trying to do for the Lua community at large.
On August 7th, Vhyrro messaged me after noticing someone had uploaded malicious rockspecs, `bcrcewon-1.0.rockspec` and `7e0b94029db0`, to luarocks.org. I suggested we notify you and Hisham and gave him Hisham's e-mail address (which I had in my address book, since I had been in touch with him before and based on prior experience knew you were hard to reach). Vhyrro found your Gmail address and sent you an email on August 7th:
--- > I've noticed that somebody on luarocks.org has uploaded two potentially malicious rockspecs: [...] These two packages contain luajit bytecode instead of traditional Lua code, which means they could contain some sort of sandbox escape and could have done some damage on the actual server itself, and may be worth investigating. Coincidentally, I've been researching this exploit vector myself over the past week, but in isolation and on my local docker run of luarocks-site. It's entirely plausible that luajit bytecode has some out-of-bounds read or write which could spell trouble for the real site, which is why I am writing you with such concern. I haven't dissected the bytecode yet, and so I can't test if it works, but it might be worth preemptively rolling out a fix. Maybe a check that disallows bytecode uploads? Seeing someone attempt a similar thing on the main luarocks site is not good news, so I recommend having a look on the main server to see if anything got compromised. ---
On August 14th, Vhyrro told me he had achieved full RCE (reproduced locally on his docker instance). He spent the next day cleaning up his POC to make it consistently reproducible. On August 15th, he sent you a second follow-up email to your Gmail address. We agreed to wait for a response for 2 weeks and then look for alternate channels to reach you on. On August 16th, he told me he was considering messaging Hisham because his previous email to you about the guy pentesting your site had gone unanswered. A day later, Vhyrro again asked me if we should try reaching out to you on other channels. I urged him to give it some time because we know you & Hisham maintain LuaRocks in your free time, and we don't want to contribute to FOSS maintainer burnout.
On August 20th, we joined the official luarocks matrix room (#luarocks_luarocks:gitter.im) and found your personal Matrix handle. That's when Vhyrro DM'd you on Matrix.
Finally, on September 10th, over a month after his initial warning about the live attack and weeks after his follow-ups regarding the RCE PoC, having received no response across email or Matrix, Vhyrro submitted the report to CERT/CC.
Regarding your comment on Lux: Dismissing our work as LLM "vibe coding" (it's not) and claiming we acted out of self-interest is an unfair personal attack. We did all we could to try and warn you early while giving you enough time to address a severe issue without causing unnecessary panic.
I just searched my email and found nothing. Do you have subject line, sender address or receipt or anything that would help me find the emails that were sent?
> found your personal Matrix handle. That's when Vhyrro DM'd you on Matrix.
I don't use Matrix. There's a gitter.im for Luarocks that's effectively dead. I last was there in January 2026 asking if the server was alive but never returned. I logged into gitter right now to check and I was able to find a DM request from August 20th, I wouldn't have seen this under any normal circumstances though
Well, thanks for sharing you attempted to contact me at least.
In my lua-like sandbox I disabled all escape hatches and unsafe functions physically by #ifndef SANDBOX. No IO, no FFI, no byte code loading, no memory funcs and such.