From 8e23ba8b17675a54477c8c812e7533afd41159ab Mon Sep 17 00:00:00 2001 From: noctuum <25441068+noctuum@users.noreply.github.com> Date: Sun, 27 Sep 2026 23:50:55 +0500 Subject: [PATCH] Reject an empty argument list in execute_lua `lua.execute` with no arguments dereferenced `args.begin()`. --- src/rpc/lua.cc | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/src/rpc/lua.cc b/src/rpc/lua.cc index c1f5c703..28e98ef0 100644 --- a/src/rpc/lua.cc +++ b/src/rpc/lua.cc @@ -394,6 +394,10 @@ execute_lua(LuaEngine* engine, rpc::target_type target_type, torrent::Object con switch (raw_args.type()) { case torrent::Object::TYPE_LIST: { const torrent::Object::list_type& args = raw_args.as_list(); + + if (args.empty()) + throw torrent::input_error("Too few arguments."); + if (flags & LuaEngine::flag_string) { check_lua_status(l_state, luaL_loadstring(l_state, args.begin()->as_string().c_str())); } else {