Lumiverse
Lumiverse: vulnerabilities and CVEs
Lumiverse has 5 published vulnerabilities, 5 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months5
Critical4
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44451 | Critical (9.3) | 0.41% | — | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window,… |
| CVE-2026-44450 | Critical (9.9) | 0.68% | — | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process… |
| CVE-2026-44449 | Critical (9.1) | 0.86% | — | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirname/basename split and only validates the directory prefix. The basename… |
| CVE-2026-44444 | Critical (9.1) | 0.66% | — | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the static backend safety scan… |
| CVE-2026-44443 | Medium (4.8) | 0.18% | — | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP request or bind the… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.