Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41196

31
FAUCET Score

OVERVIEW: CVE-2026-41196 is a sandbox escape vulnerability affecting Luanti (formerly Minetest) versions 5.0.0 through 5.15.1. The flaw allows malicious mods to break out of the Lua sandboxed environment and execute arbitrary code with full filesystem access on affected systems. This vulnerability impacts server-side mods, asynchronous environments, mapgen functions, and client-side mod (CSM) environments, but only when the game engine is compiled with LuaJIT support. SEVERITY: The vulnerability requires minimal attack complexity, as exploiting it requires only the installation of a malicious mod. While a CVSS score was not assigned, the FAUCET risk score of 52.0/100 indicates moderate to significant concern. Successful exploitation grants attackers complete code execution and filesystem access, representing a critical impact to system confidentiality, integrity, and availability. The attack vector is local and dependent on user interaction (mod installation). EXPLOITATION STATUS: There is no evidence of active exploitation in the wild, as this vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and appears inactive on threat tracking lists. The EPSS score of 0.0007 suggests minimal real-world exploitation probability. However, a patch is available in version 5.15.2, and an interim mitigation has been published for users unable to upgrade immediately.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0.0, < 5.15.2CPE matchmatch criteria
cpe:2.3:a:minetest:minetest:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.0CRITICAL

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.37%
Probability of exploitation in next 30 days
EPSS Percentile
30.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 7th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2026-41196Important

luanti: minetest: luajit: Luanti (Minetest): Arbitrary code execution and full filesystem access via malicious mod sandbox escape

Apr 23, 2026

References

github.com / luanti-org/luanti/commit/8a929dfb97aa08337f49ba1bb96a56d6557dc896
Patch
github.com / luanti-org/luanti/security/advisories/GHSA-g596-mf82-w8c3
Third Party Advisory