CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-22208

Critical · CVSS 9.6

OpenS100 — Unrestricted Lua interpreter RCE via unsandboxed luaL_openlibs()

CVSS
9.6
nvd
EPSS
0.92%
56th pct
KEV
No
Class
oss containerizable
CWE-749, CWE-829

Description

OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerability via an unrestricted Lua interpreter. The Portrayal Engine initializes Lua using luaL_openlibs() without sandboxing or capability restrictions, exposing standard libraries such as 'os' and 'io' to untrusted portrayal catalogues. An attacker can provide a malicious S-100 portrayal catalogue containing Lua scripts that execute arbitrary commands with the privileges of the OpenS100 process when a user imports the catalogue and loads a chart.

Search profile — drives PoC discovery

Symbols luaL_openlibsPortrayalEngineportrayal catalogueosioluaL_newstatelua_pcallluaL_loadfileluaL_dofilePortrayalCatalogueS-100
Keywords CVE-2026-22208OpenS100Lua RCEluaL_openlibs sandboxS-100 portrayal catalogue exploitOpenS100 Lua arbitrary command executionS100ExpertTeam OpenS100 vulnerability753cf29OpenS100 RCE PoC
Versions: prior to commit 753cf294434e8d3961f20a567c4d99151e3b530d

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z