Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix runtime files. Package names like ../../package are not properly filtered and pass the validity check of the rockspec verification system. This causes the uploaded file to be stored at the relative path location. If planned carefully, this could overwrite a runtime file and cause the website to crash. This vulnerability is fixed by 0.1.1.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Sep 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lumen
Lumen luanox |
|
Vendors & Products |
Lumen
Lumen luanox |
Tue, 16 Sep 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 16 Sep 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix runtime files. Package names like ../../package are not properly filtered and pass the validity check of the rockspec verification system. This causes the uploaded file to be stored at the relative path location. If planned carefully, this could overwrite a runtime file and cause the website to crash. This vulnerability is fixed by 0.1.1. | |
Title | Relative Path Traversal in Luanox | |
Weaknesses | CWE-22 CWE-23 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-16T18:26:11.699Z
Reserved: 2025-09-12T12:36:24.635Z
Link: CVE-2025-59336

Updated: 2025-09-16T17:29:09.926Z

Status : Awaiting Analysis
Published: 2025-09-16T17:15:42.047
Modified: 2025-09-17T14:18:55.093
Link: CVE-2025-59336

No data.