PT-2025-47979 · Lunary Ai · Lunary

Published

2025-11-25

·

Updated

2025-12-30

·

CVE-2025-9803

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary versions prior to 1.9.35
Description The application is susceptible to account takeover due to flawed authentication within the Google OAuth integration. Specifically, the application does not validate the aud (audience) field present in the access token provided by Google. The aud field confirms the intended recipient of the token, and its absence of verification allows attackers to leverage tokens issued to malicious applications to gain unauthorized access to user accounts. The vulnerable component is the Google OAuth integration process.
Recommendations lunary-ai/lunary versions prior to 1.9.35 should be updated to version 1.9.35 or later.

Exploit

Fix

Incorrect Authorization

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9803

Affected Products

Lunary