CVE-2024-5386
- EPSS 0.08%
- Veröffentlicht 02.02.2026 10:36:23
- Zuletzt bearbeitet 11.02.2026 21:03:48
In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user with a 'viewer' role can exploit this vulnerability to hijack another user's account by obtaining the password reset token. The vu...
CVE-2024-4147
- EPSS 0.06%
- Veröffentlicht 02.02.2026 10:36:22
- Zuletzt bearbeitet 11.02.2026 21:14:06
In lunary-ai/lunary version 1.2.13, an insufficient granularity of access control vulnerability allows users to delete prompts created in other organizations through ID manipulation. The vulnerability stems from the application's failure to validate ...
CVE-2025-9803
- EPSS 0.12%
- Veröffentlicht 25.11.2025 00:00:35
- Zuletzt bearbeitet 30.12.2025 17:16:19
lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth integration. The application fails to verify the 'aud' (audience) field in the access token issued by Google, which is crucial for...
CVE-2025-5352
- EPSS 0.09%
- Veröffentlicht 23.08.2025 06:56:09
- Zuletzt bearbeitet 26.11.2025 17:12:30
A critical stored Cross-Site Scripting (XSS) vulnerability exists in the Analytics component of lunary-ai/lunary versions up to 1.9.23, where the NEXT_PUBLIC_CUSTOM_SCRIPT environment variable is directly injected into the DOM using dangerouslySetInn...
CVE-2025-4779
- EPSS 0.15%
- Veröffentlicht 07.07.2025 09:53:10
- Zuletzt bearbeitet 03.12.2025 20:33:57
lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attacker can inject malicious JavaScript into the `v1/runs/ingest` endpoint by adding an empty `citations` field, triggering a code path...
CVE-2024-11300
- EPSS 0.08%
- Veröffentlicht 20.03.2025 10:11:19
- Zuletzt bearbeitet 15.10.2025 13:15:39
In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view s...
CVE-2024-10272
- EPSS 0.12%
- Veröffentlicht 20.03.2025 10:11:06
- Zuletzt bearbeitet 15.10.2025 13:15:34
lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any dataset without any kind of authorization by sending a GET request to the /v1/datasets endpoint without a valid authorization token...
CVE-2024-8998
- EPSS 0.13%
- Veröffentlicht 20.03.2025 10:11:04
- Zuletzt bearbeitet 04.04.2025 09:15:16
A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server uses the regex /{.*?}/ to match user-controlled strings. In the default JavaScript regex engine, this regex can take polynomial ti...
CVE-2025-0281
- EPSS 0.08%
- Veröffentlicht 20.03.2025 10:10:44
- Zuletzt bearbeitet 28.03.2025 14:22:53
A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier. An attacker can inject malicious JavaScript into the SAML IdP XML metadata, which is used to generate the SAML login redirect URL. This URL is th...
CVE-2024-9099
- EPSS 0.07%
- Veröffentlicht 20.03.2025 10:10:37
- Zuletzt bearbeitet 10.04.2025 15:42:18
In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such as Viewers or Prompt Editors. This vulnerability allows unauthorized users to retrie...