PT-2025-12244 · Unknown · Lunary-Ai/Lunary

Published

2025-03-20

·

Updated

2025-07-02

·

CVE-2024-8765

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary version git afc5df4
Description The privilege check mechanism in lunary-ai/lunary is flawed, allowing unauthenticated attackers to access sensitive endpoints by including "/auth/" in the path. This is because the system incorrectly identifies certain endpoints as public if the path contains "/auth/" anywhere within it. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.
Recommendations For version git afc5df4, consider restricting access to sensitive endpoints that may be incorrectly identified as public due to the presence of "/auth/" in their paths, until a proper fix is available. Additionally, as a temporary workaround, avoid using paths that contain "/auth/" for sensitive endpoints to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-8765

Affected Products

Lunary-Ai/Lunary