From abd4a79acbdfcea0bb661b8065ef3ac8f3e25e80 Mon Sep 17 00:00:00 2001 From: ShadowNinja Date: Wed, 2 Mar 2016 23:59:42 -0500 Subject: [PATCH] Remove debug.getupvalue from the Lua sandbox whitelist This function could be used to steal insecure environments from trusted mods. --- src/script/cpp_api/s_security.cpp | 1 - 1 file changed, 1 deletion(-) diff --git a/src/script/cpp_api/s_security.cpp b/src/script/cpp_api/s_security.cpp index 36f8e9c0d..730235c7b 100644 --- a/src/script/cpp_api/s_security.cpp +++ b/src/script/cpp_api/s_security.cpp @@ -116,7 +116,6 @@ void ScriptApiSecurity::initializeSecurity() "upvaluejoin", "sethook", "debug", - "getupvalue", "setlocal", }; static const char *package_whitelist[] = {