PT-2025-38061 · Luanox · Luanox

Vhyrro

·

Published

2025-09-16

·

Updated

2025-09-17

·

CVE-2025-59336

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Luanox versions prior to 0.1.1
Description Luanox is a module host for Lua packages. A file traversal vulnerability can cause a denial of service by overwriting Phoenix runtime files. Package names, such as ../../package, are not properly filtered during rockspec verification, allowing files to be stored at unintended relative path locations. This could potentially overwrite runtime files and cause the website to crash.
Recommendations Update to version 0.1.1 or later.

Exploit

Fix

DoS

Relative Path Traversal

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-59336
GHSA-42C5-X4PJ-4P3W

Affected Products

Luanox