A vulnerability, which was classified as critical, has been found in libinput. This issue affects some unknown processing of the component Lua Handler. The manipulation leads to code injection.

This vulnerability is uniquely identified as CVE-2026-35093. Local access is required to approach this attack. No exploit exists.