Junglewise Threat Intelligence

CVE-2026-44444: Lumiverse RCE via untrusted lifecycle scripts in Spindle extensions

CVE-2026-44444 · Severity: critical · CVSS 9.1 · Published 2026-05-26

Technologies: Prolix-Oc Lumiverse. Vendors: Prolix-Oc.

Executive brief

Lumiverse is an AI chat application that allows users to install extensions to add new features. A security flaw in the extension installation process allows a malicious extension to run unauthorized commands on the server hosting the application. If an administrator installs or updates a compromised extension, an attacker could gain full control over the server, potentially leading to data theft or service disruption.

Technical details

The Spindle extension build pipeline in Lumiverse fails to use the --ignore-scripts flag when executing 'bun install' during the extension installation or update process. This occurs in the manager service before the static backend safety scan (assertSafeBackendBundle) is performed. An attacker with administrative privileges can provide a malicious extension containing lifecycle hooks (such as preinstall or postinstall) in the package.json file. These scripts are executed with the privileges of the server process, leading to host-level remote code execution (RCE). The vulnerability is fixed in version 0.9.7 by ensuring scripts are ignored during the build process.

Affected products

  • prolix-oc Lumiverse < 0.9.7

Timeline

  • 2026-05-06: advisory: Original GitHub security advisory published
  • 2026-05-26: disclosed: CVE published to NVD

References

Related threats