VYPR

Lumiverse

by Nicepkg

CVEs (1)

  • CVE-2026-44443MedMay 26, 2026
    risk 0.31cvss 4.8epss

    Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate any value from the incoming HTTP request or bind the nonce to the admin's session. If the admin's…