minetest CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

minetest vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to minetest, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-41196 Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to execute arbitrary code and gain full filesystem access on the user's device. This applies to the server-side mod, async and mapgen as well as the client-side (CSM) environments. This vulnerability is only exploitable when using LuaJIT. Version 5.15.2 contains a patch. On release versions, one can al [email protected] 9.0 0.37% 2026-04-23 2026-05-14
CVE-2022-35978 Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then loaded as soon as the game session is exited. The Lua environment the menu runs in is not sandboxed and can directly interfere with the user's system. There are currently no known workarounds. [email protected] 7.7 2.20% 2022-08-15 2024-11-21
CVE-2022-24301 In Minetest before 5.4.0, players can add or subtract items from a different player's inventory. [email protected] 6.5 0.97% 2022-02-02 2024-11-21
CVE-2022-24300 Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection. [email protected] 9.8 1.64% 2022-02-02 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence