Search CVE reports


Toggle filters

1 – 4 of 4 results


CVE-2026-41196

Medium priority

Some fixes available 4 of 5

Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to execute arbitrary code and...

2 affected packages

luanti, minetest

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
luanti Fixed Not in release Not in release — —
minetest Not in release Fixed Fixed Fixed Not affected
Show less packages

CVE-2022-35978

Medium priority
Needs evaluation

Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as...

1 affected package

minetest

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
minetest Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-24301

Low priority
Needs evaluation

In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.

1 affected package

minetest

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
minetest Not in release Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2022-24300

Medium priority
Needs evaluation

Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.

1 affected package

minetest

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
minetest Not in release Not affected Not affected Needs evaluation Needs evaluation
Show less packages