PT-2025-47979 · Lunary Ai · Lunary
Published
2025-11-25
·
Updated
2025-12-30
·
CVE-2025-9803
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary versions prior to 1.9.35
Description
The application is susceptible to account takeover due to flawed authentication within the Google OAuth integration. Specifically, the application does not validate the
aud (audience) field present in the access token provided by Google. The aud field confirms the intended recipient of the token, and its absence of verification allows attackers to leverage tokens issued to malicious applications to gain unauthorized access to user accounts. The vulnerable component is the Google OAuth integration process.Recommendations
lunary-ai/lunary versions prior to 1.9.35 should be updated to version 1.9.35 or later.
Exploit
Fix
Incorrect Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lunary