CVE-2020-14939: Freedroid Freedroidrpg
High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.
An issue was discovered in savestruct_internal.c in FreedroidRPG 1.0rc2. Saved game files are composed of Lua scripts that recover a game's state. A file can be modified to put any Lua code inside, leading to arbitrary code execution while loading.
Affected products
- Freedroid Freedroidrpg: version 1.0 only
Published 2020-06-23. Last modified 2026-06-17.