PT-2026-5650 · Lunary Ai · Lunary
Published
2026-02-02
·
Updated
2026-02-11
·
CVE-2024-4147
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
lunary-ai/lunary version 1.2.13
Description
An insufficient granularity of access control allows users to delete prompts created in other organizations through ID manipulation. The application does not validate the ownership of the prompt before deletion, only checking for deletion permissions without verifying organizational affiliation. This can lead to legitimate users being unable to access removed prompts and cause information inconsistencies.
Recommendations
Ensure proper validation of prompt ownership before allowing deletion operations.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lunary