Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Prolix-oc
Prolix-oc lumiverse |
|
| Vendors & Products |
Prolix-oc
Prolix-oc lumiverse |
Tue, 26 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the static backend safety scan (assertSafeBackendBundle). A malicious extension that ships a package.json with a preinstall, postinstall, or prepare lifecycle script achieves host-level code execution the moment an admin presses Install before any dist file is inspected. This vulnerability is fixed in 0.9.7. | |
| Title | Lumiverse: Spindle extension install runs untrusted lifecycle scripts before security scan | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-27T14:09:18.240Z
Reserved: 2026-05-06T15:49:25.192Z
Link: CVE-2026-44444
Updated: 2026-05-27T14:08:06.853Z
Status : Deferred
Published: 2026-05-26T21:16:37.897
Modified: 2026-06-17T10:50:39.150
Link: CVE-2026-44444
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:08:31Z