File Traversal Vulnerability in Luanox Module for Lua Packages
CVE-2025-59336

6.9MEDIUM

Key Information:

Vendor

Lumen-oss

Status
Vendor
CVE Published:
16 September 2025

What is CVE-2025-59336?

The Luanox module, designed to host Lua packages, is susceptible to a file traversal vulnerability prior to version 0.1.1. This issue arises when certain package names, such as ../../package, are inadequately filtered, enabling harmful files to be uploaded to relative path locations without robust validity checks through the rockspec verification system. As a result, an attacker could overwrite critical Phoenix runtime files, potentially leading to service disruptions or crashes of the affected website. Users are advised to upgrade to version 0.1.1 to mitigate this vulnerability.

Affected Version(s)

luanox < 0.1.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59336 : File Traversal Vulnerability in Luanox Module for Lua Packages