PT-2025-12034 · Unknown · Lunary-Ai/Lunary

Published

2025-03-20

·

Updated

2025-07-02

·

CVE-2024-10273

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary version 1.5.0
Description The issue is related to improper privilege management in the models.ts file, which allows users with viewer roles to modify models owned by others. The "PATCH" endpoint for models lacks appropriate privilege checks, enabling low-privilege users to update models they should not have access to modify. This could lead to unauthorized changes in critical resources, affecting the integrity and reliability of the system.
Recommendations For lunary-ai/lunary version 1.5.0, consider disabling the models.ts file or restricting access to the "PATCH" endpoint for models until a patch is available. Additionally, restrict the viewer role from modifying models to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2024-10273

Affected Products

Lunary-Ai/Lunary