Three new vulnerabilities have been discovered in the Lua scripting engine of Redis 7.4.5, each of which poses serious risks for remote code execution and privilege escalation. Redrays published a detailed proof-of-concept (PoC) exploit for these vulnerabilities, but it is no longer available to the public. However, organizations are urged to take immediate action to protect their systems.

Lua scripting engine – Redis: Use-After-Free vulnerability (CVE-2025-49844)
This vulnerability occurs when TString objects are not properly protected during script parsing. Specifically, in luaY_parser, the Lua parser fails to protect a new TString, making it vulnerable to “premature garbage collection” and “use-after-free conditions.” Attackers can exploit this issue for remote code execution.
See also: CISA added Zimbra vulnerability to KEV Catalog
Lua scripting engine – Redis: Integer Overflow (CVE-2025-46817)
The unpack() function incorrectly calculates the number of elements, allowing stack corruption when called with extreme range parameters. By modifying the arguments, such as unpack({1,2,3}, -2, 2147483647), attackers could bypass array bounds and execute arbitrary code.
Lua scripting engine: Metatable Privilege Escalation Vulnerability (CVE-2025-46818)
This vulnerability allows modification of basic metatables, such as those for strings and numbers, because they are not properly protected (as read-only). By modifying the metatables, a malicious user could achieve privilege escalation or code execution in the context of other users.

RedRays said a robust Python-based PoC exploit verifies the criticality of all three vulnerabilities. The PoC automates:
- Aggressive heap and garbage collection stress tests for use-after-free exploitation (CVE-2025-49844)
- Fuzzing of unpack() call to cause integer overflow and stack corruption (CVE-2025-46817)
- Manipulation of basic metatables types to demonstrate privilege escalation via crafted Lua scripts (CVE-2025-46818)
See also: Vulnerability in Kibana Crowdstrike Connector exposes protected credentials
The code connects to a targeted Redis instance and runs up to ten full-stack tests, confirming exploitability and the presence or absence of a proper patch.
These technical checks leverage custom Lua scripts sent via Redis EVAL commands, revealing vulnerable server states.
See also: Exploiting OpenSSH vulnerability via ProxyCommand

Protection
Redis administrators should update to patched versions immediately. These CVEs collectively expand the attack surface of Redis, exposing production servers to real threats, especially where EVAL access is available. Organizations running Redis 7.4.5 should deploy patches without delay, as attackers can exploit these vulnerabilities to achieve full remote code execution and unauthorized privilege escalation. Immediate patching is required for all Redis deployments that are exposed to the internet (or untrusted).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
