Code Injection Vulnerability in Lumiverse AI Chat Application by Prolix
CVE-2026-44451

9.3CRITICAL

Key Information:

Vendor

Prolix-oc

Status
Vendor
CVE Published:
26 May 2026

What is CVE-2026-44451?

Lumiverse, a versatile AI chat application, contains a code injection vulnerability that allows attackers to bypass security controls. Prior to version 0.9.7, the application’s component override system lacked sufficient validation, allowing user-supplied TSX code to be executed. The vulnerability arises from the misuse of the new Function constructor and a static source validator that can be circumvented. Attackers can reconstruct blocked identifier strings at runtime, gaining access to dangerous globals like the window object. This presents a significant risk, as a malicious theme pack can be exploited by unsuspecting users, triggering the payload in their authenticated sessions upon importing and enabling certain components. This issue has been addressed in version 0.9.7, highlighting the importance of updating to secure applications against potential exploitation.

Affected Version(s)

Lumiverse < 0.9.7

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.