CVE-2026-40960

EUVD-2026-23151
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 6.59%
Debian logo
Debian Releases
Debian Product
Codename
luanti
forky
5.15.2+dfsg-2
fixed
sid
5.15.2+dfsg-2
fixed
trixie
5.10.0+dfsg-5+deb13u1
fixed
trixie (security)
5.10.0+dfsg-5+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
luanti
jammy
dne
noble
dne
questing
Fixed 5.10.0+dfsg-5+deb13u1build0.25.10.1
released
resolute
Fixed 5.10.0+dfsg-5+deb13u1build0.26.04.1
released