Description
Apache APISIX - Remote Code Execution Admin API script injection via loadstring. --- The Bug APISIX allows defining route logic via a script field. The script is compiled and executed using Lua's loadstring with zero sanitization. Vulnerable code —...
Basic Information
ID
A850288C-3512-5B06-84FB-869F100C7956
Published
Jan 10, 2026 at 15:39
Modified
Jan 10, 2026 at 15:48