Minetest is a sandbox-style voxel game engine that prioritizes lightweight, open-source game development and server hosting; its vulnerability profile centers on a single core product with security exposure rooted in code-injection vectors and permission-handling weaknesses typical of extensible game-scripting environments. The recurring weakness classes—including improper code generation control, incorrect default permissions, and protection mechanism failures—reflect the inherent tension between enabling modding flexibility and constraining untrusted script execution. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Minetest over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41196CRITICAL Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed | Apr 23, 2026 | 10.0 | 31 | NO | NO |
CVE-2022-35978CRITICAL Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to di | Aug 15, 2022 | 10.0 | 31 | NO | NO |
CVE-2022-24300CRITICAL Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection. | Feb 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-24301MEDIUM In Minetest before 5.4.0, players can add or subtract items from a different player's inventory. | Feb 2, 2022 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Minetest.
Media articles that mention a CVE ID that affects a product developed by Minetest — matched by CVE ID, not by vendor name.