File Traversal Vulnerability in Luanox Module for Lua Packages
CVE-2025-59336
6.9MEDIUM
What is CVE-2025-59336?
The Luanox module, designed to host Lua packages, is susceptible to a file traversal vulnerability prior to version 0.1.1. This issue arises when certain package names, such as ../../package, are inadequately filtered, enabling harmful files to be uploaded to relative path locations without robust validity checks through the rockspec verification system. As a result, an attacker could overwrite critical Phoenix runtime files, potentially leading to service disruptions or crashes of the affected website. Users are advised to upgrade to version 0.1.1 to mitigate this vulnerability.
Affected Version(s)
luanox < 0.1.1