« Volver al listado

CVE-2026-44451

Estado: AplazadaCrítica (9.3)—

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window, eval, etc.) with undefined. A static source validator (validateComponentOverrideSource) additionally blocks these identifiers by word-boundary regex. Both controls are bypassed. String-split bypass of the static validator: any blocked identifier can be reconstructed at runtime from string fragments ('ownerDoc' + 'ument').

Leer descripción completaMostrar menos

DOM ref escape from the sandbox: useRef and useEffect are provided in scope. A ref attached to a rendered element gives a live DOM node. From any real DOM node, node['ownerDoc'+'ument']['def'+'aultView'] yields the real window, bypassing all identifier shadows. Theme packs (.lumitheme / .lumiverse-theme) are the shareable delivery mechanism. A malicious pack is an exploit path: the victim imports the file, enables one component override in the Theme Editor, and the payload fires in their authenticated session.This vulnerability is fixed in 0.9.7.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UI:R + transpilación de código TSX evaluado con new Function → T1203 (ejecución en cliente). Acceso a DOM, window y contexto autenticado permite ejecutar comandos, leer datos y actuar como el usuario.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-44451",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-44451",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-27T17:26:03.744696Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.3,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "prolix-oc",
          "product": "Lumiverse",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.9.7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-26T21:16:38.303",
  "references": [
    {
      "url": "https://github.com/prolix-oc/Lumiverse/security/advisories/GHSA-rgp6-55rw-5xf4",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/prolix-oc/Lumiverse/security/advisories/GHSA-rgp6-55rw-5xf4",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-693"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window, eval, etc.) with undefined. A static source validator (validateComponentOverrideSource) additionally blocks these identifiers by word-boundary regex. Both controls are bypassed. String-split bypass of the static validator: any blocked identifier can be reconstructed at runtime from string fragments ('ownerDoc' + 'ument'). DOM ref escape from the sandbox: useRef and useEffect are provided in scope. A ref attached to a rendered element gives a live DOM node. From any real DOM node, node['ownerDoc'+'ument']['def'+'aultView'] yields the real window, bypassing all identifier shadows. Theme packs (.lumitheme / .lumiverse-theme) are the shareable delivery mechanism. A malicious pack is an exploit path: the victim imports the file, enables one component override in the Theme Editor, and the payload fires in their authenticated session.This vulnerability is fixed in 0.9.7."
    },
    {
      "lang": "es",
      "value": "Lumiverse es una aplicación de chat de IA con todas las funciones. Anteriormente a la 0.9.7, el sistema de anulación de componentes transpila TSX proporcionado por el usuario a través de Sucrase y lo evalúa con new Function, ocultando globales peligrosos (fetch, window, eval, etc.) con undefined. Un validador de código fuente estático (validateComponentOverrideSource) adicionalmente bloquea estos identificadores mediante expresiones regulares de límite de palabra. Ambos controles son eludidos. Elusión del validador estático mediante división de cadenas: cualquier identificador bloqueado puede ser reconstruido en tiempo de ejecución a partir de fragmentos de cadena ('ownerDoc' + 'ument'). Escape de referencia DOM desde la sandbox: useRef y useEffect se proporcionan en el ámbito. Una referencia adjunta a un elemento renderizado proporciona un nodo DOM en vivo. Desde cualquier nodo DOM real, node['ownerDoc'+'ument']['def'+'aultView'] produce la ventana real, eludiendo todas las ocultaciones de identificadores. Los paquetes de temas (.lumitheme / .lumiverse-theme) son el mecanismo de entrega compartible. Un paquete malicioso es una ruta de exploit: la víctima importa el archivo, habilita una anulación de componente en el Editor de Temas, y la carga útil se activa en su sesión autenticada. Esta vulnerabilidad se corrige en la versión 0.9.7."
    }
  ],
  "lastModified": "2026-07-24T11:10:00.170",
  "sourceIdentifier": "security-advisories@github.com"
}