Redis Lua sandbox escape
benmmurphy.github.io
benmmurphy.github.io
it is a very good write up. it was not too difficult to convert it to 64 bit.
i'm fairly sure the demo page on the lua website is vulnerable: http://www.lua.org/demo.html but lua-5.3 is a little different fro lua-5.1 so i don't have a working exploit for this. but they let you load bytecode.
If you have a very adversarial security model, do not offer your users any chance to run in-process Turing-complete scripts. But if you do want that feature, Lua is the best language I can think of (at least that is not a LISP).
Lua bytecode has been known to be vulnerable for a long time, which is why there is no more bytecode sanitizer in the language. If you load untrusted code from Lua, always use mode "t". This is documented in Lua 5.3: http://www.lua.org/manual/5.3/manual.html#pdf-load
If you want to implement a Lua sandbox, start with this post by Lua author: http://lua-users.org/lists/lua-l/2013-12/msg00406.html and this repository by a prominent member of the Lua community: https://github.com/kikito/sandbox.lua