Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-44443— Lumiverse: Sign-up nonce race condition allows unauthorized account registration

CVSS 4.8 · Medium EPSS 0.03% · P8

Possible ATT&CK Techniques 1AI

T1133 · External Remote Services

Affected Version Matrix 1

VendorProductVersion RangeStatus
prolix-ocLumiverse< 0.9.7affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-44443

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Lumiverse: Sign-up nonce race condition allows unauthorized account registration
Source: NVD (National Vulnerability Database)
Vulnerability Description
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP request or bind the nonce to the admin's session. If the admin's auth.api.signUpEmail() call fails before the before hook fires (e.g. BetterAuth rejects a duplicate email at the validation layer), the nonce is set but never consumed. Any POST /api/auth/sign-up/email request that arrives during the remaining window registers successfully regardless of who sent it. An attacker who can observe or predict when the admin is creating users (must be a dupplicate user) can race the 10-second window to register an unauthorized account. This vulnerability is fixed in 0.9.7.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Lumiverse 竞争条件问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Lumiverse是Prolix OCs个人开发者的一个全功能AI聊天应用套件。 Lumiverse 0.9.7之前版本存在竞争条件问题漏洞,该漏洞源于consumeNonce()仅检查模块级变量是否设置且未过期,未验证HTTP请求中的任何值或将nonce绑定到管理员会话,攻击者可在管理员创建用户时竞争10秒窗口注册未授权账户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
prolix-ocLumiverse < 0.9.7 -

II. Public POCs for CVE-2026-44443

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-44443

登录查看更多情报信息。

Vendor Advisories for CVE-2026-44443 (1)

Same Patch Batch · prolix-oc · 2026-05-26 · 5 CVEs total

CVE-2026-444509.9 CRITICALLumiverse: RCE via MCP stdio argument injection
CVE-2026-444519.3 CRITICALLumiverse: TSX component sandbox escape via DOM ref and string-split identifier bypass
CVE-2026-444499.1 CRITICALLumiverse: SMB `exists()` basename injection via smbclient `!cmd` escape
CVE-2026-444449.1 CRITICALLumiverse: Spindle extension install runs untrusted lifecycle scripts before security scan

IV. Related Vulnerabilities

V. Comments for CVE-2026-44443

No comments yet


Leave a comment