PT-2024-34582 · Lunary Ai · Lunary

Published

2024-06-06

·

Updated

2025-10-15

·

CVE-2024-5126

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary versions 1.2.2 through 1.2.24
Description An improper access control issue exists in the versions.patch functionality for updating prompts, allowing unauthorized users to update prompt details due to insufficient access control checks. This issue was addressed and fixed in a later version.
Recommendations For versions 1.2.2 through 1.2.24, update to version 1.2.25 to resolve the issue. As a temporary workaround, consider restricting access to the versions.patch functionality until the update is applied.

Exploit

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-5126

Affected Products

Lunary