Actively Exploited in the Wild
This vulnerability is being actively exploited in the wild.
dendibakh perf-ninja Code Injection Vulnerability in Lua Modules
Vulnerability
A code injection vulnerability has been identified in the perf-ninja project by dendibakh, specifically within the Lua modules related to profile-guided optimization. The issue arises from improper control over code generation, allowing potentially malicious code to be executed. This vulnerability is linked to the program file 'ldo.C'.
Impact
Exploitation of this vulnerability allows for code injection, where an attacker can introduce and execute arbitrary code within the application.
Remediation
Users are advised to update to the latest version of perf-ninja, where this vulnerability has been addressed by disabling the loading of Lua bytecode, which could be exploited to inject malicious code.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
