Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it. | |
| Weaknesses | CWE-670 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-16T01:20:26.427Z
Reserved: 2026-04-16T00:54:45.558Z
Link: CVE-2026-40960
No data.
Status : Received
Published: 2026-04-16T01:16:11.770
Modified: 2026-04-16T01:16:11.770
Link: CVE-2026-40960
No data.
OpenCVE Enrichment
No data.