
CVE-2026-40959 Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod. https://www.cve.org/CVERecord?id=CVE-2026-40959
Post summary
CVE-2026-40959 was disclosed for Luanti 5 before 5.15.2, where LuaJIT enables a sandbox escape through a crafted module. No PoC, exploit, or patch details are mentioned.


