{"id":"CVE-2026-22208","summary":"OpenS100 Portrayal Engine Unrestricted Lua Standard Library Access","details":"OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerability via an unrestricted Lua interpreter. The Portrayal Engine initializes Lua using luaL_openlibs() without sandboxing or capability restrictions, exposing standard libraries such as 'os' and 'io' to untrusted portrayal catalogues. An attacker can provide a malicious S-100 portrayal catalogue containing Lua scripts that execute arbitrary commands with the privileges of the OpenS100 process when a user imports the catalogue and loads a chart.","modified":"2026-08-12T03:51:39.327410285Z","published":"2026-02-17T14:29:05.423Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"753cf294434e8d3961f20a567c4d99151e3b530d"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulnCheck","cwe_ids":["CWE-749","CWE-829"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22208.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22208.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22208"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/opens100-portrayal-engine-unrestricted-lua-standard-library-access"},{"type":"FIX","url":"https://github.com/S-100ExpertTeam/OpenS100/commit/753cf294434e8d3961f20a567c4d99151e3b530d"},{"type":"PACKAGE","url":"https://github.com/S-100ExpertTeam/OpenS100"},{"type":"EVIDENCE","url":"https://www.mdpi.com/1424-8220/26/4/1246"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/s-100expertteam/opens100","events":[{"introduced":"0"},{"fixed":"753cf294434e8d3961f20a567c4d99151e3b530d"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22208.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}