← Vulnerability feed

Vulnerability record · CVE-2023-32700 · published 20 May 2023

CVE-2023-32700: Luatex project luatex command injection vulnerability

LLuatex Project · Luatex

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

7.8 CVSS 3.1 High EPSS 0.80% · top 45.0% CWE-77 · Command injection
7.8CVSS 3.1 base score
0.80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-32700 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10243Debian linux improper input validation vulnerabilityTeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.EPSS 7.1%8.8CVE-2017-17513Tug tex live injection vulnerabilityTeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow rem…EPSS 1.3%7.8CVE-2018-17407Tug tex live memory buffer overflow vulnerabilityAn issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling …EPSS 2.1%6.8CVE-2010-0827Tug tex live vulnerabilityInteger overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possib…EPSS 4.4%6.8CVE-2010-1440Tug tetex vulnerabilityMultiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of servic…EPSS 3.4%6.8CVE-2010-0739Tug tetex vulnerabilityInteger overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to exe…EPSS 4.9%5.5CVE-2023-32668Luatex project luatex vulnerabilityLuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to th…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2023-32700), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.