PT-2025-12035 · Unknown · Lunary-Ai/Lunary
Published
2025-03-20
·
Updated
2025-07-02
·
CVE-2024-10274
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary version 1.5.5
Description
An improper authorization issue exists due to inadequate access control mechanisms in the "/users/me/org" endpoint, allowing unauthorized users to access sensitive team member information, including names, roles, and emails, which can lead to privacy violations and potential targeted attacks.
Recommendations
For lunary-ai/lunary version 1.5.5, consider restricting access to the "/users/me/org" endpoint until a patch is available, and review the access control mechanisms to ensure they are adequate to prevent unauthorized access.
Exploit
Fix
Improper Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lunary-Ai/Lunary