CVE-2026-40960 Details
Description
Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the request for the insecure environment or HTTP API, and also receive access to it.
A vulnerability in Luanti versions 5.0.0 prior to 5.15.2 allows unintended access to an insecure environment. If a mod is listed as secure.trusted_mods or secure.http_mods, a crafted mod can intercept requests to the insecure environment or HTTP API and gain access to them. This issue arises because the function 'getCurrentModName' can be manipulated by a malicious mod to override its return value, potentially leading to unauthorized access.
Users can update to Luanti version 5.15.2 or later, or clear the 'secure.trusted_mods' and 'secure.http_mods' settings to disable access for all mods.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-670 | Always-Incorrect Control Flow Implementation | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | New CVE Received | [email protected] |