CVE-2023-32668
LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentation. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.
Published:May 11, 2023
Last Modified:Nov 3, 2025
EPS:May 11, 2023
EPSS Score:0.00058
CVSS Score:5.5
Affected Products
Vendor
Product
Action
Vendor
Luatex Project
Product
Luatex
Luatex Project
Luatex
Vendor
Miktex
Product
Miktex
Miktex
Miktex
Vendor
Tug
Product
Tex Live
Tug
Tex Live
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
