Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input, aka ItemStack meta injection.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "5.4.1+repack-2build1", "binary_name": "minetest" }, { "binary_version": "5.4.1+repack-2build1", "binary_name": "minetest-data" }, { "binary_version": "5.4.1+repack-2build1", "binary_name": "minetest-dbgsym" }, { "binary_version": "5.4.1+repack-2build1", "binary_name": "minetest-server" }, { "binary_version": "5.4.1+repack-2build1", "binary_name": "minetest-server-dbgsym" } ] }