Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6217-1 | luanti security update |
Fri, 17 Apr 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Crafted Module Enables Unauthorized Access to Insecure Environment in Luanti |
Thu, 16 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Apr 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Luanti
Luanti luanti |
|
| Vendors & Products |
Luanti
Luanti luanti |
Thu, 16 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it. | |
| Weaknesses | CWE-670 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-16T12:31:57.082Z
Reserved: 2026-04-16T00:54:45.558Z
Link: CVE-2026-40960
Updated: 2026-04-16T12:22:21.432Z
Status : Awaiting Analysis
Published: 2026-04-16T01:16:11.770
Modified: 2026-04-17T15:38:09.243
Link: CVE-2026-40960
No data.
OpenCVE Enrichment
Updated: 2026-04-17T05:00:05Z
Debian DSA