« Volver al listado

CVE-2026-44450

Estado: AplazadaCrítica (9.9)—

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation. Every binary on the allowlist accepts an inline-code execution flag (-e for node/bun, -c for python3/deno), giving any logged-in user arbitrary OS-level code execution on the Lumiverse server. The route requires only requireAuth (not requireOwner). The server binds on all interfaces (::) and the host-header rebinding check is bypassed trivially by any HTTP client that sends Host: localhost:<port> directly, making this exploitable from any machine with network access to the server port. This vulnerability is fixed in 0.9.7.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/PR:L permite acceso remoto autenticado a endpoint vulnerable. Args sin validación + flags inline (-e, -c) permiten ejecución de comandos arbitrarios. Host-header bypass trivial expande alcance a cualquier cliente con acceso de red.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-44450",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-44450",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-01T17:03:56.285972Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.1
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "prolix-oc",
          "product": "Lumiverse",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.9.7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-26T21:16:38.173",
  "references": [
    {
      "url": "https://github.com/prolix-oc/Lumiverse/security/advisories/GHSA-mfwv-ch2f-9j5v",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-88"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation. Every binary on the allowlist accepts an inline-code execution flag (-e for node/bun, -c for python3/deno), giving any logged-in user arbitrary OS-level code execution on the Lumiverse server. The route requires only requireAuth (not requireOwner). The server binds on all interfaces (::) and the host-header rebinding check is bypassed trivially by any HTTP client that sends Host: localhost:<port> directly, making this exploitable from any machine with network access to the server port. This vulnerability is fixed in 0.9.7."
    },
    {
      "lang": "es",
      "value": "Lumiverse es una aplicación de chat de IA con todas las funciones. Antes de la 0.9.7, el endpoint de creación del servidor MCP valida el campo de comando contra una lista de permitidos de nombres de binarios, pero reenvía el array de argumentos al proceso hijo sin ninguna validación. Cada binario en la lista de permitidos acepta un flag de ejecución de código en línea (-e para node/bun, -c para python3/deno), otorgando a cualquier usuario autenticado la ejecución arbitraria de código a nivel de sistema operativo en el servidor Lumiverse. La ruta solo requiere requireAuth (no requireOwner). El servidor se enlaza a todas las interfaces (::) y la verificación de re-enlace del encabezado Host se omite trivialmente por cualquier cliente HTTP que envíe Host: localhost:<port> directamente, haciendo esto explotable desde cualquier máquina con acceso de red al puerto del servidor. Esta vulnerabilidad se corrigió en la 0.9.7."
    }
  ],
  "lastModified": "2026-07-24T11:10:00.170",
  "sourceIdentifier": "security-advisories@github.com"
}