Back

CRITICAL

Lumiverse: Spindle extension install runs untrusted lifecycle scripts before security scan

Published May 26, 2026

Description

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the static backend safety scan (assertSafeBackendBundle). A malicious extension that ships a package.json with a preinstall, postinstall, or prepare lifecycle script achieves host-level code execution the moment an admin presses Install before any dist file is inspected. This vulnerability is fixed in 0.9.7.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 26, 2026
Updated May 27, 2026
Reserved May 6, 2026
CISA Vulnrichment
Updated May 27, 2026
NVD
Status Deferred
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published May 26, 2026
Updated May 27, 2026
Exploited since n/a
EUVD-2026-31981