VYPR

Lumiverse

by Lumiverse

CVEs (1)

  • CVE-2026-44450May 26, 2026
    risk 0.00cvss epss

    Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation. Every binary on the allowlist accepts an…