CVE-2024-39840: Factorio
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain Lua base module functions to execute bytecode and generate fake objects.
Affected products
- Factorio Factorio: before 1.1.101 (fixed in 1.1.101)
Published 2024-06-29. Last modified 2026-06-17.