« Back to list

Lumiverse

Lumiverse: vulnerabilities and CVEs

Lumiverse has 5 published vulnerabilities, 5 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months5
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-44451Critical (9.3)0.41%—May 26, 2026
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window,…
CVE-2026-44450Critical (9.9)0.68%—May 26, 2026
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process…
CVE-2026-44449Critical (9.1)0.86%—May 26, 2026
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirname/basename split and only validates the directory prefix. The basename…
CVE-2026-44444Critical (9.1)0.66%—May 26, 2026
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the static backend safety scan…
CVE-2026-44443Medium (4.8)0.18%—May 26, 2026
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP request or bind the…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter4
  2. T1210 Exploitation of Remote Services3
  3. T1203 Exploitation for Client Execution1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.