Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-44451— Lumiverse: TSX component sandbox escape via DOM ref and string-split identifier bypass

CVSS 9.3 · Critical EPSS 0.04% · P12

Affected Version Matrix 1

VendorProductVersion RangeStatus
prolix-ocLumiverse< 0.9.7affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-44451

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Lumiverse: TSX component sandbox escape via DOM ref and string-split identifier bypass
Source: NVD (National Vulnerability Database)
Vulnerability Description
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window, eval, etc.) with undefined. A static source validator (validateComponentOverrideSource) additionally blocks these identifiers by word-boundary regex. Both controls are bypassed. String-split bypass of the static validator: any blocked identifier can be reconstructed at runtime from string fragments ('ownerDoc' + 'ument'). DOM ref escape from the sandbox: useRef and useEffect are provided in scope. A ref attached to a rendered element gives a live DOM node. From any real DOM node, node['ownerDoc'+'ument']['def'+'aultView'] yields the real window, bypassing all identifier shadows. Theme packs (.lumitheme / .lumiverse-theme) are the shareable delivery mechanism. A malicious pack is an exploit path: the victim imports the file, enables one component override in the Theme Editor, and the payload fires in their authenticated session.This vulnerability is fixed in 0.9.7.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
保护机制失效
Source: NVD (National Vulnerability Database)
Vulnerability Title
Lumiverse 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Lumiverse是Prolix OCs个人开发者的一个全功能AI聊天应用套件。 Lumiverse 0.9.7之前版本存在安全漏洞,该漏洞源于组件覆盖系统通过Sucrase转译用户提供的TSX并用new Function评估,静态验证器和全局变量遮蔽均可被绕过,字符串分割可绕过静态验证器,DOM引用可逃逸沙箱获取真实window对象,恶意主题包导入后启用组件覆盖即可在用户认证会话中触发有效载荷。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
prolix-ocLumiverse < 0.9.7 -

II. Public POCs for CVE-2026-44451

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-44451

登录查看更多情报信息。

Vendor Advisories for CVE-2026-44451 (1)

Same Patch Batch · prolix-oc · 2026-05-26 · 5 CVEs total

CVE-2026-444509.9 CRITICALLumiverse: RCE via MCP stdio argument injection
CVE-2026-444499.1 CRITICALLumiverse: SMB `exists()` basename injection via smbclient `!cmd` escape
CVE-2026-444449.1 CRITICALLumiverse: Spindle extension install runs untrusted lifecycle scripts before security scan
CVE-2026-444434.8 MEDIUMLumiverse: Sign-up nonce race condition allows unauthorized account registration

IV. Related Vulnerabilities

V. Comments for CVE-2026-44451

No comments yet


Leave a comment