
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24827 is an Out-of-bounds Write vulnerability (CWE-787) in gerstrong's Commander-Genius, an open-source Commander Keen game engine reimplementation. The flaw exists in Lua scripting components (GsKit/base/lua/ldebug.c and GsKit/base/lua/lvm.c) that were cloned from the upstream Lua repository but did not receive a prior security patch (lua/lua@42d4058, originally tracked as CVE-2022-33099). All versions before the fix introduced in pull request #358/merge (merged December 29, 2025) are affected. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, GitHub PR #379).
The root cause is an out-of-bounds write (CWE-787) in the Lua interpreter components bundled within Commander-Genius — specifically in GsKit/base/lua/ldebug.c and GsKit/base/lua/lvm.c. These files were copied from the upstream Lua repository but missed the security patch (commit 42d4058) that addressed stack space exhaustion during error handling, which can lead to memory corruption. The vulnerability is network-reachable (AV:N), requires no authentication or user interaction, and has low attack complexity, meaning a remote attacker can trigger it by sending crafted input that causes the Lua runtime to perform an out-of-bounds write. The fix applies the same patch from the upstream Lua project to the cloned code (GitHub PR #379).
Successful exploitation results in a denial-of-service condition by crashing the Commander-Genius application, with high availability impact. The CVSS vector indicates no confidentiality or integrity impact, limiting the practical consequence to application unavailability. Given that Commander-Genius is a game engine rather than a server-side enterprise application, the blast radius is generally limited to individual users or game sessions, with no evidence of lateral movement potential (Feedly).
Users should update Commander-Genius to any version incorporating the fix from pull request #379 (merged into the master branch on December 29, 2025), which applies the upstream Lua security patch (commit 42d4058) to GsKit/base/lua/ldebug.c and GsKit/base/lua/lvm.c. No configuration-based workaround is available; upgrading to a patched build is the only recommended remediation. Organizations using Qualys can use detection ID 916742 to identify unpatched instances (GitHub PR #379).
The vulnerability was responsibly disclosed by researcher tlnguyen-smu, who submitted pull request #379 to the Commander-Genius repository and received prompt acknowledgment and merge from the project owner (gerstrong) on December 29, 2025. The project owner also expressed interest in adopting Lua as a Git submodule to better track upstream security patches in the future. No broader media coverage or notable community discussion beyond the GitHub pull request has been identified (GitHub PR #379).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."