OVERVIEW: CVE-2026-41196 is a sandbox escape vulnerability affecting Luanti (formerly Minetest) versions 5.0.0 through 5.15.1. The flaw allows malicious mods to break out of the Lua sandboxed environment and execute arbitrary code with full filesystem access on affected systems. This vulnerability impacts server-side mods, asynchronous environments, mapgen functions, and client-side mod (CSM) environments, but only when the game engine is compiled with LuaJIT support. SEVERITY: The vulnerability requires minimal attack complexity, as exploiting it requires only the installation of a malicious mod. While a CVSS score was not assigned, the FAUCET risk score of 52.0/100 indicates moderate to significant concern. Successful exploitation grants attackers complete code execution and filesystem access, representing a critical impact to system confidentiality, integrity, and availability. The attack vector is local and dependent on user interaction (mod installation). EXPLOITATION STATUS: There is no evidence of active exploitation in the wild, as this vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and appears inactive on threat tracking lists. The EPSS score of 0.0007 suggests minimal real-world exploitation probability. However, a patch is available in version 5.15.2, and an interim mitigation has been published for users unable to upgrade immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.15.2CPE matchmatch criteria | cpe:2.3:a:minetest:minetest:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.