VYPR

Vendor CVEs

Lumiverse

All CVEs

83 total · sorted by risk
  • CVE-2026-44450CriMay 26, 2026
    risk 0.64cvss 9.9epss 0.00

    Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation. Every binary on the allowlist accepts an…

  • CVE-2024-39015CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.01

    cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-39013CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.01

    2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-36575CriJun 17, 2024
    risk 0.64cvss 9.8epss 0.01

    A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.

  • CVE-2020-28440CriDec 11, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.

  • CVE-2020-28439CriDec 11, 2020
    risk 0.64cvss 9.8epss 0.02

    This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:

  • CVE-2020-7726CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function.

  • CVE-2020-7725CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function.

  • CVE-2020-7723CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function.

  • CVE-2020-7721CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.

  • CVE-2020-7718CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.

  • CVE-2020-7716CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package deeps are vulnerable to Prototype Pollution via the set function.

  • CVE-2020-7604CriMar 15, 2020
    risk 0.64cvss 9.8epss 0.03

    pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the attacker. This function uses the variable "filename" to construct the argument of the exec call without any sanitization. In order to…

  • CVE-2020-7603CriMar 15, 2020
    risk 0.64cvss 9.8epss 0.03

    closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be controlled by users without any sanitization.

  • CVE-2020-8128CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.03

    An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.

  • CVE-2019-10769CriDec 6, 2019
    risk 0.64cvss 9.8epss 0.03

    safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to Arbitrary Code Execution via generating a RangeError.

  • CVE-2026-47430CriJun 8, 2026
    risk 0.62cvss epss 0.01

    ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside the InAppBrowser…

  • CVE-2020-28435CriJul 25, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.

  • CVE-2018-12519HigJun 19, 2018
    risk 0.61cvss 8.8epss 0.06

    An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious file to a Node.js application. An attacker can upload a malicious HTML file that contains a JavaScript payload to steal a user's credentials.

  • CVE-2026-44451CriMay 26, 2026
    risk 0.60cvss 9.3epss 0.00

    Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window, eval, etc.) with undefined. A static source validator…

  • CVE-2026-44449CriMay 26, 2026
    risk 0.59cvss 9.1epss 0.00

    Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirname/basename split and only validates the directory prefix. The basename is concatenated directly into the smbclient -c script…

  • CVE-2026-44444CriMay 26, 2026
    risk 0.59cvss 9.1epss 0.00

    Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the static backend safety scan (assertSafeBackendBundle). A malicious extension that ships a package.json…

  • CVE-2019-19723criSep 4, 2020
    risk 0.59cvss epss 0.00

    All versions of `passport-cognito` are vulnerable to Improper Authorization. The package fails to properly scope the variables containing authorization information, such as access token, refresh token and ID token. This causes a race condition where simultaneous authenticated…

  • CVE-2017-16034criSep 1, 2020
    risk 0.59cvss epss 0.00

    Affected versions of `pidusage` pass unsanitized input to `child_process.exec()`, resulting in arbitrary code execution in the `ps` method. This package is vulnerable to this PoC on Darwin, SunOS, FreeBSD, and AIX. Windows and Linux are not vulnerable. ## Proof of Concept…

  • CVE-2026-9961HigMay 28, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in SurfaceCapture in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2020-7722CriSep 1, 2020
    risk 0.57cvss 9.8epss 0.02

    All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.

  • CVE-2020-7634CriApr 6, 2020
    risk 0.57cvss 9.8epss 0.03

    heroku-addonpool through 0.1.15 is vulnerable to Command Injection.

  • CVE-2020-7672HigJun 10, 2020
    risk 0.56cvss 8.6epss 0.02

    mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed by the `eval` function, resulting in code execution.

  • CVE-2023-26129HigMay 27, 2023
    risk 0.55cvss 8.4epss 0.01

    All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwm-ng.js file. **Note:** To execute the code snippet and potentially exploit the vulnerability, the attacker needs to have the ability to…

  • CVE-2024-39016HigJul 1, 2024
    risk 0.53cvss 8.1epss 0.01

    che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2021-39135HigAug 31, 2021
    risk 0.53cvss 8.2epss 0.01

    `@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed…

  • CVE-2021-39134HigAug 31, 2021
    risk 0.53cvss 8.2epss 0.01

    `@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed…

  • CVE-2020-7739HigOct 6, 2020
    risk 0.53cvss 8.2epss 0.01

    This affects all versions of package phantomjs-seo. It is possible for an attacker to craft a url that will be passed to a PhantomJS instance allowing for an SSRF attack.

  • CVE-2026-34713HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition.…

  • CVE-2026-34711HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.00

    CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue…

  • CVE-2026-9956HigMay 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-9496HigMay 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and…

  • CVE-2024-22363HigApr 5, 2024
    risk 0.49cvss 7.5epss 0.01

    SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).

  • CVE-2020-7687HigJul 25, 2020
    risk 0.49cvss 7.5epss 0.02

    This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.

  • CVE-2020-7683HigJul 25, 2020
    risk 0.49cvss 7.5epss 0.02

    This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.

  • CVE-2019-5417HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.

  • CVE-2019-5416HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the remote server.

  • CVE-2018-11615HigAug 30, 2018
    risk 0.49cvss 7.5epss 0.02

    This vulnerability allows remote attackers to deny service on vulnerable installations of npm mosca 2.8.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of topics. A crafted regular expression can cause the broker to…

  • CVE-2018-10813HigJun 5, 2018
    risk 0.48cvss 7.3epss 0.02

    In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of…

  • CVE-2020-28455HigJul 25, 2022
    risk 0.47cvss 7.3epss 0.01

    This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

  • CVE-2024-32753HigJul 11, 2024
    risk 0.46cvss epss 0.00

    Under certain circumstances the camera may be susceptible to known vulnerabilities associated with the JQuery versions prior to 3.5.0 third-party component

  • CVE-2016-1000227higSep 1, 2020
    risk 0.46cvss epss 0.01

    All versions of `bootstrap-tagsinput` are vulnerable to cross-site scripting when user input is passed into the `itemTitle` parameter unmodified, as the package fails to properly sanitize or encode user input for that parameter. ## Recommendation This package is not actively…

  • CVE-2018-8046MedJul 5, 2018
    risk 0.45cvss 6.1epss 0.43

    The getTip() method of Action Columns of Sencha Ext JS 4 to 6 before 6.6.0 is vulnerable to XSS attacks, even when passed HTML-escaped data. This framework brings no built-in XSS protection, so the developer has to ensure that data is correctly sanitized. However, the getTip()…

  • CVE-2019-16777HigDec 13, 2019
    risk 0.43cvss 7.7epss 0.02

    Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any…

  • CVE-2019-16776HigDec 13, 2019
    risk 0.43cvss 7.7epss 0.03

    Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher…

Page 1 of 2