CVE-2026-44444
Lumiverse, an AI chat application, is vulnerable to host-level code execution in versions before 0.9.7 when a malicious extension includes harmful npm lifecycle scripts. The flaw occurs because the Spindle extension build pipeline runs bun install without the --ignore-scripts flag before a safety scan. This issue is resolved in Lumiverse version 0.9.7.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Lumiverse versions prior to 0.9.7
Real-world impact
An attacker can achieve arbitrary code execution on the host when an administrator installs a malicious extension.
Why this severity
CVSS v3.1 base score 9.1 (Critical) due to network attack vector, low complexity, high privileges required, no user interaction, and high impacts to confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Lumiverse to version 0.9.7 or later.
NVD-referenced vendor advisory
Timeline
- May 26, 2026 · May 26, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.