PT-2025-12244 · Unknown · Lunary-Ai/Lunary
Published
2025-03-20
·
Updated
2025-07-02
·
CVE-2024-8765
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary version git afc5df4
Description
The privilege check mechanism in lunary-ai/lunary is flawed, allowing unauthenticated attackers to access sensitive endpoints by including "/auth/" in the path. This is because the system incorrectly identifies certain endpoints as public if the path contains "/auth/" anywhere within it. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.
Recommendations
For version git afc5df4, consider restricting access to sensitive endpoints that may be incorrectly identified as public due to the presence of "/auth/" in their paths, until a proper fix is available. Additionally, as a temporary workaround, avoid using paths that contain "/auth/" for sensitive endpoints to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lunary-Ai/Lunary