{"id":"CVE-2026-71235","published":"2026-08-05T11:16:26.247","lastModified":"2026-08-10T12:17:25.983","description":"Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database access), ioutil (file I/O), an HTTP client (SSRF), and filepath (traversal).","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://github.com/absmach/magistrala","tags":[]}],"exploitRefs":[{"url":"https://github.com/absmach/magistrala","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows authenticated users to execute arbitrary Lua scripts, leading to remote code execution (RCE) and potential data exfiltration or system compromise.","exploitability":"Exploitation is relatively straightforward for authenticated users with access to the rules engine, requiring only the ability to craft and submit Lua scripts.","blast_radius":"If exploited, the impact could be severe, potentially leading to full control over the affected system and data breaches.","remediation":"Disable the Lua script feature or restrict access to the rules engine to only trusted users.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","lua","auth","exploit","server-side"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:19:22.088Z"}}