Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

dendibakh perf-ninja Code Injection Vulnerability in Lua Modules

Vulnerability

A code injection vulnerability has been identified in the perf-ninja project by dendibakh, specifically within the Lua modules related to profile-guided optimization. The issue arises from improper control over code generation, allowing potentially malicious code to be executed. This vulnerability is linked to the program file 'ldo.C'.

Impact

Exploitation of this vulnerability allows for code injection, where an attacker can introduce and execute arbitrary code within the application.

Remediation

Users are advised to update to the latest version of perf-ninja, where this vulnerability has been addressed by disabling the loading of Lua bytecode, which could be exploited to inject malicious code.

Added: Mar 24, 2026, 5:19 AM
Updated: Mar 24, 2026, 5:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
9.1
remediation
0.0
relevance
4.4
threat
8.0
urgency
5.7
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.