Executive brief
Lumiverse is an AI chat application. A security flaw in how the application handles SMB (file sharing) connections allows an administrative user to execute arbitrary commands on the server. This could lead to a full system takeover, unauthorized access to sensitive data, or disruption of services.
Technical details
A command injection vulnerability exists in the SMBFileSystem.exists() method of Lumiverse. The application attempts to validate paths using toSmbPath(), but if that call fails, it falls back to a dirname/basename split where only the directory component is validated. The unvalidated basename is then concatenated into an smbclient script. An attacker can use the ';' subcommand separator and the '!' local-shell escape character within a filename to execute arbitrary commands on the host. This requires 'Owner' or 'Admin' privileges and is reachable via the connection testing and validation API endpoints. The issue is fixed in version 0.9.7.
Affected products
- prolix-oc Lumiverse < 0.9.7
- npm lumiverse-backend <= 0.9.5
Timeline
- 2026-05-06: advisory: Vendor advisory published on GitHub
- 2026-05-26: disclosed: CVE published to NVD
- 2026-05-26: patched: Fix released in version 0.9.7