CVE-2026-44449
Lumiverse, an AI chat application, contains a path‑handling flaw in versions before 0.9.7 that allows an attacker to execute arbitrary commands on the server by crafting a malicious file path. The issue is resolved in version 0.9.7, which validates both directory and basename components before passing them to smbclient.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Lumiverse versions prior to 0.9.7
Real-world impact
An attacker with the ability to influence the input path can achieve remote code execution on the Lumiverse server with the privileges of the application.
Why this severity
CVSS v3.1 score 9.1 (Critical) due to network‑adjacent attack vector, low attack complexity, high privileges required, and high impact on confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Lumiverse to version 0.9.7 or later.
NVD description (fix noted in version 0.9.7)
Timeline
- May 26, 2026 · May 26, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.