- Sources: writeup, discussion
- Summary: The writeup traces the chain end to end, starting from a LuaJIT bytecode instruction the sandbox did not account for. The author states the outcome as root access on the server, and the demonstration described in the body runs against a local Docker copy of luarocks-site rather than the live registry, so the root-access outcome is the author's claim rather than an observed compromise of LuaRocks.org. The sandbox itself was carefully built, and the defeat came from the registry accepting precompiled bytecode rather than source only. The writeup assigns no CVE identifier and names no affected luarocks-site version, so the affected range is not yet known.
- Why it matters: The writeup shows a well built Lua sandbox defeated entirely by accepting precompiled bytecode, which is the same mistake any registry that evaluates user-supplied manifests in-process can make.
- Follow-up: The LuaRocks incident led the 2026-09-27 digest and now has a complete public exploit chain, so track remediation on the registry and whether other package registries that accept bytecode respond.
send feedback on this story