CVE-2026-41196
Severity CVSS v4.0:
CRITICAL
Type:
CWE-94
Code Injection
Publication date:
23/04/2026
Last modified:
14/05/2026
Description
Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to execute arbitrary code and gain full filesystem access on the user's device. This applies to the server-side mod, async and mapgen as well as the client-side (CSM) environments. This vulnerability is only exploitable when using LuaJIT. Version 5.15.2 contains a patch. On release versions, one can also patch this issue without recompiling by editing `builtin/init.lua` and adding the line `getfenv = nil` at the end. Note that this will break mods relying on this function (which is not inherently unsafe).
Impact
Base Score 4.0
9.00
Severity 4.0
CRITICAL
Base Score 3.x
10.00
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:minetest:minetest:*:*:*:*:*:*:*:* | 5.0.0 (including) | 5.15.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



