Commenters discussed a reported remote-code-execution path in LuaRocks centered on LuaJIT bytecode and loadstring, with several people noting that loadstring can accept bytecode and that unsafe evals break sandboxes. xx_ns and others compared it to a Project Zomboid mod RCE where loadstring was the entry point and said removing loadstring or hardening sandboxes is a practical mitigation. rurban described disabling escape hatches (IO, FFI, bytecode loading) in their sandbox, and xx_ns linked a Project Zomboid write-up showing the approach was quickly patched there.
Much of the debate focused on disclosure and conduct. leafo, who runs luarocks.org, accused the researchers of sitting on the vulnerability, failing to contact him directly, submitting through CISA instead, and testing the exploit on production without proper disclosure - claims he says complicated incident response. mrcjkb, a Lux co-maintainer, countered with a detailed timeline saying Vhyrro emailed and messaged maintainer contacts beginning August 7, followed up, joined the project chat when email went unanswered, and eventually reported to CERT/CC after delays; he also pushed back on leafo’s characterization of their motives as “LLM vibe coding.” Opinion divides on whether the researchers’ outreach was sufficient and whether exercising the exploit on production without clearer disclosure was ethical versus a reasonable step after failed contact attempts.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.